TOP SECRET//SLWOFORN 



Version 17 (Final) 
Last Updated 09/07/1 1 
Includes CAO Review feedback 



COURSE: (TS//S I //NF) OVSC1205 Special Training on FISA (Analytical) 
COURSE: (TS//S I //NF) OVSC1206 Special Training on FISA (Technical) 

Module 1: (TS//S I //NF) Business Records (BR) and Pen Register Trap and Trace (PR/TT) Bulk Metadata Programs 



DATE/PREPARER: TAP 



Topic 

(U) Module 
Introduction 



Home 



Page Classification 

TOP SECRET//S I //NOFORN 



Screen Number 
1 of 12 



Exit 



Glossary 



Next 



FRAME ID: 1010 



NEXT FRAME ID: 1020 



BACK FRAME ID: n/a 



ALT TAG: 



GRAPH IC/AV: 

(U) Present learning objectives in the travel 
journal 



(U) MODULE 1 

( TS//S I //NF ) Business Records (BR) and Pen Register Trap and Trace (PR/TT) Bulk 
Metadata Programs 

(U) This module will enable you to: 

• (TS//S I //NF) Identify the purpose of the BR and PR/TT Bulk Metadata Programs 

• (TS//S I //NF) Identify the ^HForeign Powers covered by the BR and PR/TT Foreign 
Intelligence Surveillance Court (FISC) Orders 

• (TS//S I //NF) Contrast the differences in the authorities granted between BR FISC 
Orders and PR/TT FISC Orders 

• (TS//S I //NF) Recognize the role of the Bulk Metadata Programs in the context of the 
broader set of SIGINT authorities 



( TS//S I //NF ) (OGC Attorney): During the first part of our road trip we will discuss the Business Records (BR) and Pen Register Trap and Trace (PR/TT) 
Bulk Metadata Programs at a high level. As we progress on our road trip, we will discuss various aspects of the authorities granted by the Foreign 
Intelligence Surveillance Court (FISC) which support the BR and PR/TT programs and the policies that NSA implements to provide reasonable assurance 
that we are compliant with these authorities. 
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(U) This module will enable you to: 

• ( TS//S I //NF ) Identify the purpose of the BR and PR/TT Bulk Metadata Programs 

• (TS//SI//NF) Identify the ^Jporeign Powers covered by the BR and PR/TT Foreign Intelligence Surveillance Court (FISC) Orders 

• (TS//SI//NF)^^^^^^^^^^| in the authorities granted between BR FISC Orders and PR/TT FISC Orders 

• ( TS//S I //NF ) Recognize the role of the Bulk Metadata Programs in the context of the broader set of SIGINT authorities 
Scroll over text for foreign powers: 

( TS//S I //NF ) Under the FISA statute, a foreign power can include "a group engaged in international terrorism or activities in preparation therefore. 
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(TS//SI//NF) The purpose of the BR and PR/TT Bulk Metadata Programs is to support 
the Counterterrorism mission. 

(TS//SI//NF) Bull< metadata consists of "unselected" communications events, and the 
BR and PR/TT Bull< Metadata programs complement NSA's traditional selection-based 
intelligence collection. 



( TS//S I //NF ) (OGC Attorney): The BR and PR/TT programs are supported by two special authorities granted by the FISC which permit NSA to obtain 
telephony and internet communications bulk metadata from U.S. -based telecommunications service providers. The authority was granted by the FISC in 
support of the Counterterrorism mission to permit NSA to learn more about a terrorist target's communications, even those terrorists potentially 
located in the United States. 



( TS//S I //NF ) Bulk metadata consists of "unselected" communications events, and the BR and PR/TT Bulk Metadata Programs complement NSA's 
traditional selection-based intelligence collection. 

( TS//S I //NF ) As you can probably imagine, bulk internet and telephony metadata, acquired within the United States, contains information to, from, or about 
U.S. persons. Therefore, because there is unminimized U.S. person information included within this type of metadata, there are special rules and 
procedures we must follow when acquiring, processing, accessing, storing, sharing, and disseminating this information. This metadata is highly sensitive 
which is why we have this specialized training. 

( TS//S I //NF ) In this course we discuss the metadata we collect, how we collect it, what we are permitted to do with it as well as other special rules and 
procedures we must follow. 
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( TS//S I //NF ) (OGC Attorney): To get started, let's discuss the individual Bulk Metadata Programs. The BR Program pertains to the acquisition of telephony 
metadata. The associated FISC Order allows NSA to ask specific U.S.-based telecommunications service providers for their business records. The 
business records, also known as call detail records, contain information about phone calls. 



roqram and associated FISC Order permits the collection of bulk Internet communications metadata. 




( TS//S I //NF ) Under both these FISC orders, NSA is prohibite^ranj^cqu^^ content. Under these Prograr ns, NSA may not listen to 

phone calls, or collect the body or subject of an email ^^^^^^^^^^H^^l The Bulk Metadata authorities permit the| 
about the communications. 



( TS//S I //NF ) In Module 2, we will explore how each type of metadata is obtained and what specific information each order permits NSA to collect. 
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( TS//S I //NF ) (OGC Attorney): Due to the sensitivity of the data and the desire to protect the privacy of U.S. persons, the FISC imposes restrictions on how 
we can touch the data. For the purposes of this course, by "touch" we mean any activity where there is an opportunity to commit a violation with regards to 
the Orders governing these authorities. We recognize that it takes a very diverse team of individuals working to see that the data is properly acquired, 
routed, prepared, stored, then queried, shared and disseminated. From acquisition to dissemination, including management and compliance, if you play a 
role in enabling this data to be used for its intelligence value, we consider you to be someone who "touches" this data. 

( TS//S I //NF ) NSA's goal is to provide reasonable assurance that we are complying with the law AND making the most of these authorities to support the 
counterterrorism mission and protect the United States. 
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( TS//S I //NF ) (OGC Attorney): BR and PR/TT are two separate orders issued by the FISC, though the general access, sharing, dissemination, and retention 
rules are the same for the two programs. Those similarities are why the training for both is covered in t his course. Additio nalj v, both Orders target the same 
jrouDS. referred to in the Orders as the Foreign Powers. The Foreign Pow ers named in the orders aref 

I Both the BR and PR/TT prog 

Articulable Suspicion, or RAS, to gain approval to guery the bulk metadata with an identifier. We will get into much more detail about these two topics in 
later modules. 
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( TS//S I //NF ) (OGG Attorney): There are two high level differences between the Orders as well. Details of the differences wil 
but at a basic level, the biqqest difference between the two Programs is how the metadata is obtained. 



be addressed in later modules, 




( TS//S I //NF ) The other point where the Bulk Metadata Programs differ is in the area of hop restrictions for contact chaining. This will be described in detail 
in Module 4, but for now it is important to know that according to the Orders the hop restrictions are different for the BR and PR/TT Programs. 
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( TS//S I //NF ) (OGC Attorney): NSA must reapply to the FISC every 90 days to continue operating under these authorities. This process allows for the 
Government to seek modifications and for the FISC to update these authorities to reflect changes that may affect NSA's collection and handling of BR and 
PR/TT bulk metadata. It is also crucial that all factors associated with NSA's implementation of these programs are fully compliant with the FISC Orders 
and guidelines. 

( TS//S I //NF ) As new orders are issued, this training may be augmented to address significant changes. Your organization will notify you if or when 
additional training is necessary. Should you have questions, you are strongly encouraged to contact your manager, Counterterrorism (CT) Homeland 
Security Analysis Center (HSAC), Technology Directorate (TD) Compliance, SID Oversight and Compliance, or the Office of General Counsel (OGC) for 
assistance and guidance. 
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( TS//S I //NF ) NSA may perform SIGINT functions under various FISA authorities to include: 

• NSA FISA 

• FBI FISA 

• FAA Section 702 

• FAA Section 704 

• FAA Section 705(b) 

( TS//S I //NF ) BR and PR/TT Bulk Metadata Programs provide analysts with another opportunity to gain unique 
collection on a target 

( TS//S I //NF ) By leveraging various collection authorities, analysts can fill existing knowledge gaps on their 
target 



( TS//S I //NF ) (OGC Attorney): Now that you have a better understanding of what the BR and PR/TT Bulk Metadata Programs are, you may be wondering 
where these programs fit in the context of the broader set of SIGINT authorities. 



( TS//S I //NF ) Recall from OVSC1100, the Overview of Signals Intelligence Authorities, that we learned that in addition to E.O. 12333, NSA may perform 
SIGINT functions under various FISA authorities to include NSA FISA, FBI FISA, FISA Amendments Act (FAA) Section 702, 704, and 705(b). While there 
are specific rules governing when and how these authorities may be applied, each of these authorities has the potential to provide a valuable and unique 
complement to our E.O. 12333 collection resources. Similarly, the BR and PR/TT Bulk Metadata Programs provide analysts with another opportunity to 
gain unique collection on a target. By leveraging as many of these various collection authorities available to them as permitted, analysts can fill existing 
knowledge gaps on their target. 

( TS//S I //NF ) One prime example of how an analyst leveraged several of these collection authorities to close crucial knowledge gaps on a target occurred in 
Fall 2009, when a CT analyst pieced together information obtained from E.O. 12333, FAA 702, and BR FISA authorities to reveal a terrorist plot on the New 
York subway system, which was subsequently disrupted by the FBI. 
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( TS//SI//NF ) Similarities between SPCMA and BR & PR/TT 

(TS//5 l //Nr) Both involve exclusively metadata 

(TS//S I //Nr) Both allow for querying of U.S. person identifiers under specific circumstances 



( TS//SI//NF ) Differences between SPCMA and BR & PR/TT 



• (TS//S I //NF) Source of the metadata 
o SPCMA procedures apply to metadata 

already lawfully collected under E.G. 

12333, NSA FISA, FBI FISA, FAA 702, 704, 

and 705(b) authorities 
o BR and PR/TT programs authorize the 

acquisition of unselected, bulk metadata 



(TS//S I //Nr) To query the 
metadata: 

o SPCMA requires valid and 

documented foreign intelligence 

purpose 
o BR and PR/TT require RAS- 

approved identifier for a limited 

target set 



(TS//S I //NF) (OGC Attorney): It is also important to understand what the BR and PR/TT Bulk Metadata programs are not. You may have heard of SPCMA - 
the Supplemental Procedures Governing Communications Metadata Analysis. They allow NSA to treat communications metadata differently than content in 
the course of the analysis of communications metadata already lawfully collected under E.O. 12333, NSA FISA, FBI FISA, FAA 70 2, 704, and 705(b) 
authorities. Specifically, given a valid and documented foreign intelligence purpose, these new procedures permit contact chaining,] 
^^^^^^^^^^^^B^ommunications metadata identifier, irrespective of nationality or location, in order to follow or discover valid foreign intelligence 
targets. What SPCMA and the BR and PR/TT programs have in common, then, is that they both exclusively involve metadata, and allow for queries of 
identifiers belonging to U.S. persons. 

(TS//S I //NF) Unlike SPCMA, however, the BR and PR/TT Programs authorize the acquisition of unselected, bulk metadata. Because of the sensitivity of 
this metadata, it may only be queried with identifiers for which RAS exists to believe that the identifier is directly associated with the Foreign Powers 
specified in the Court Order granted by the FISC. You will learn much more about the RAS standard in Module 3. 
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(U) Knowledge Check 

1. ( TS//S I //NF ) What is the purpose of the BR and PR/TT Bulk Metadata Programs? 

a) (TS//S I //NF) To permit NSA to learn more about a terrorist target's communications, even 
those terrorists potentially located in the United States 

b) ( TS//S I //NF ) To give NSA the authority to collect and analyze the content of foreign and domestic 
terrorist telecommunications traffic 

c) ( TS//S I //NF ) To enable NSA to more effectivel y collect and analyze telep hony and internet 
communications metadata associated with the| 

d) (U) All of the above 

2. (TS//S I //NF) The BR and PR/TT Bulk Metadata Programs enable NSA to query identifiers related to. 

a) All terrorists regardless of their affiliation and origin. ^^^^^^^^^^ 

b) Terrorists/terrorist groups associated with Foreign Powers, ^^^^^^^^H 

c) Any foreign intelligence target. ^^^^^^^^^^^^^^ 

d) Terrorists/terrorist groups associated with 



(U) (OGC Attorney): Let's make a few notes in our travel journal and check to see what you remember from this topic! 



ANSWERS: 

Question 1 : ( TS//S I //NF ) Correct! The purpose of the BR and PR/TT Bulk Metadata Programs is to permit NSA to learn more about a terrorist target's 
communications, even those terrorists potentially located in the United States. 

( TS//S I //NF ) Incorrect. The correct answer is a). The purpose of the BR and PR/TT Bulk Metadata Programs is to permit NSA to learn more about a 
terrorist target's communications, even those terrorists potentially located in the United States. 

Quest ion 2 : ( TS//S I //NF ) Correct! The BR and PR/TT Bulk Metadata Programs enable NSA to query identifiers related to terrorists/terrorist groups who fall 
under ^iForeign Powers^^^^^^^^^H 

(TC//u l //h i ir) Incorrect. The correct answer is b). The BR and P R/TT Bulk Metadata Programs enable NSA to query identifiers related to terrorists/terrorist 
groups who fall under Foreign Powers j 
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(U) Knowledge Check 

3. ( TS//S I //NF ) One of the differences between BR and PR/TT is that the 

records delivered by the telecommunications providers, while the 

live, streaming Internet communications. 

a) bulk metadata, PR/TT metadata 

b) PR/TT metadata, bulk metadata 

c) PR/TT metadata, BR metadata 

d) BR metadata, PR/TT metadata 



4. ( TS//S I //NF ) Which of the following is true of BR and PR/TT and not other authorities? 

a) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from 
U.S.-based telecommunications service providers that may not be available from other collection 
sources, and NSA can only query that metadata for counter proliferation purposes. 

b) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain content from U.S.- 
based telecommunications service providers that may not be available from other collection 
sources, and NSA can only query that content for counterterrorism purposes. 

c) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk 
from U.S.-based telecommunications service providers that may not be available from 
other collection sources, and NSA can only query that metadata for counterterrorism 
purposes. 

d) ( TS//S I //NF ) In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from 
foreign telecommunications service providers that may not be available from other collection 
sources, and NSA can query that intelligence for any foreign intelligence purpose. 



(No audio or transcript on this page) 



ANSWERS: 

Questior^rgS/^WNF^or^^ 

. (TS//S I //N F)- Incorrect. The correct answer is d). One of the differences between BR and PR/TT is that | 



Question 4: (TS//SI#M^) Correct! In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from U.S.-based telecommunications 
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service providers tinat may not be available from other collection sources, and NSA can only query that metadata for counterterrorism purposes. 
( TS//S I //NF ) Incorrect. The correct answer is c). In the BR and PR/TT authorities, NSA is authorized to obtain metadata in bulk from U.S. -based 
telecommunications service providers that may not be available from other collection sources, and NSA can only query that metadata for 
counterterrorism purposes. 
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(U//FOUO) (OGC Attorney): Now that we have completed the first part of our road trip, you should be able to: 

• (TS//SI//NF) Identify the purpose of the BR and PR/TT Bulk Metadata Programs 

• (TS//SI//NF) Identify the^Jporeign Powers covered by the BR and PR/TT Foreign Intelligence Surveillance Court (FISC) Orders 

• (TS//SI//NF) Contrast the differences in the authorities granted between BR FISC Orders and PR/TT FISC Orders 

• (TS//SI//NF) Recognize the role of the Bulk Metadata Programs in the context of the broader set of SIGINT authorities 
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COURSE: . (TS//S I //NF) OVSC1205 Special Training on FISA (Analytical) 
COURSE: (TG//G I //Nr) OVSC1206 Special Training on FISA (Technical) 
Module 3: (U) Establishing Reasonable Articulable Suspicion (RAS) 
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(U) Module 3 

(U) Establishing Reasonable Articulable Suspicion (RAS) 

(U) This module will enable you to: 

• (TS//S I //NF) Recognize the direct relationship between the Foreign Powers and 
establishing RAS 

• (TS//S I //NF) Identify the key components of RAS and how it is applied to candidate 
identifiers 

• (TS//S I //Nr) Identify who can adjudicate and approve a RAS nomination 

• (TG//S I //Nr) Recognize the requirement associated with identifiers linked to U.S. 
persons - the OGC First Amendment Review 

• (TS//SI//NF ) List common sources of information used to construct a RAS 
nomination statement 



(TS//S I //NF) (OGC Attorney): This part of our trip will provide you with an overview of the Reasonable Articulable Suspicion (RAS) Standard including 
definitions and descriptions to help you understand how to satisfy RAS and how to apply it to identifiers under the BR and PR/TT FISC Orders. In addition 
to this training, guidance is also outlined in a RAS memo that can be obtained from the Office of General Counsel. 

(TS//3 I //NF) This module will enable you to: 

• ( T0//0 I //N r4 Recognize the direct relationship between the Foreign Powers and establishing RAS 

• (TS//S I //NF) Identify the key components of RAS and how it is applied to candidate identifiers 
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• (TS//S I //Nr ) Identify who can adjudicate and approve a RAS nomination 

• (TS//S l //hJ r) Recog n ize tine requirement associated witli identifiers linl<ed to U.S. persons - tine OGC First Amendment Review 

• (TG//G I //Nr ) List common sources of information used to construct a RAS nomination statement 

(TS//S I //Nr ) At tlie conclusion of this module you should understand that an identifier must be RAS-approved before conducting a query. The topic of 
querying BR and PR/TT bulk metadata will be discussed in Module 4. 
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■ (T S //S I //Nr) NSA is not permitted to query the BR and PR/TT metadata unless there is a 
reasonable articulable suspicion that the identifier is associated with one of the FISC- 
approved groups. 



t T0//0 l //h J r ) (OGC Attomevl^T^B^an^PR^^Order^^ under each authority. T_ 

Foreign Powers are ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^B The Orders detail f 

NSA Is not permitted to query the BR and PR/TT metadata unless there 
Is a reasonable articulable suspicion that the Identifier Is associated with one of the FISC-approved groups. 

(TS//S I //Nr) It Is Important to note that you cannot query using just anWorBi^rnntelli^enc^ar^^ 
^ar^e^^oi^AN however query using Identifiers specifically linked to| 

| as named In the Orders. Note that the lists may evolve and your target may be added or removed over time, so you should reference the 
most current version of the lists for updates. 
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(U) Reasonable Articulable Suspicion (RAS) Standard 

(TS//SI/,^iF) - An identifier will meet the Reasonable Articulable Suspicion Standard if based on 

the factual and practical considerations of everyday life on which reasonable and prudent 
persons act, there are facts giving rise to a reasonable articulable suspicion that the identifier is 
associated with one of the specified Foreign Powers. 

- Foreign Intelligence Surveillance Court 



GRAPH IC/AV: 

(U) Display pop-up with the definition of 
RAS as it is discussed. 



(TS//SI//NF) (OGC Attorney): The FISC recognizes the potential counterterrorism advantage gained through analysis of the BR and PR/TT bulk metadata; 
however, because there is a great deal of U.S. person information included in the bulk metadata, the FISC has set strict guidelines on when and how 
analysts can access the metadata under these authorities. The RAS standard is one of these guidelines which helps to provide reasonable assurance that 
only legitimate terrorism-related identifiers are used to query the bulk metadata. This standard must be met before queries can be conducted. 



(TS//S I //NF ) So what is RAS? RAS is a legal standard that describes the measure of proof required to support a decision whether to permit an identifier to 
be queried from the bulk metadata. The Reasonable Articulable Suspicion standard requires just that-a suspicion that you can explain in a reasonable way. 
It does not require certainty, but is more concrete than a simple hunch. It may be easiest to think of it in terms of other standards with which you may be 
familiar. 



i(T2//0l//r'Jr) Many of you may be familiar with legal standards of proof applicable in other situations. It may be helpful to understand how the RAS standard 
compares to these other legal standards. For example, a jury in a criminal case will not convict an accused unless the evidence of guilt is "beyond a 
reasonable doubt. "This is the highest legal standard of proof. A jury in a civil case (such as a personal injury case or a contract dispute) might award a 
plaintiff money damages if the plaintiff proves the elements of his claim by "a preponderance of the evidence." This standard is lower than "beyond a 
reasonable doubt." Lower still is the standard of proof required to justify issuance of a search warrant - "probable cause" - whether that search warrant is 
for the suspect's home or the content of the suspect's communications. The RAS standard falls below "probable cause." 
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. (TS//S I //NF) The FISC has determined that this lower standard of proof is reasonable for the querying of metadata because communications metadata 
does not carry with it the same privacy protections as communications content. The RAS standard falls below "probable cause" but above a mere hunch or 
guess. 
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Reasonable Articulable Suspicion (RAS) Standard 

(T[i//SI/<T'<ir) An identifier will meet the Reasonable Articulable Suspicion Standard if based on 

the factual and practical considerations of everyday life on which reasonable and prudent 
persons act, there are facts giving rise to a reasonable articulable suspicion that the identifier is 
associated with one of the specified Foreign Powers." 

- Foreign Intelligence Surveillance Court 



GRAPH IC/AV: 

(U) Continue to display definition of RAS 
then pull out the RAS Equation. 



RAS Equation 

Identifier + Link to Foreign Power = RAS 



■(OGC Attorney): As it applies to the B R and PR/TT Orders, RAS is a suspicion that an identifiei^ucl^^r^mai^ddrgss^ele^^ 
or other identifier type, is associated with one of the^lForeign Powers named in BR and PR/TT Orders ^^^^^^^^^^^^^^^^^^^^^^^|The 

FISC requires that NSA base that suspicion on a certain level of factual evidence - and NSA must articulate those facts that connect the identifier with one 
of the named terrorist organizations. The requirement that these facts be articulable effectively provides reasonable assurance that analyst queries of the 
metadata are based on substantive information (meaning more than simple hunches or uninformed guesswork). So in order to obtain RAS approval for an 
identifier, analysts must provide enough factual evidence that it would lead a reasonable person to suspect that an identifier is associated with one of the 
named Foreign Powers in the BR and PR/TT Orders. We will get more into the l<inds of facts that may be used and how they can support a RAS 
nomination later in this module. 

(TO//O I //Nr) In summary, based on the factual and practical considerations of everyday life 
detemiin^^her^^^^ suspicion that the identifier is associated with [ 

^^^^^^^^^^^^^^^^^^|named in the Orders. There must be at least one qualifying fact giving rise to the suspicion that the identifier is associated 
with one of the Foreign Powers listed in the BR and PR/TT Orders. Unless that determination is made, the identifier cannot be approved to query this 
metadata repository. NSA's implementation of the BR and PR^^Orders mandates that the RAS nomination statement must clearly link the identifier/target 
to one of the Foreign Powers and document this finding in ^^^^^B whic h will be discussed later in the module. 
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(TS//SI//NF) (HMC Chaiaulet). Ftoiii an Aiialybis and Pioduuliun standpoint, let's look at RAS in the context of the analyst level of effoit lequiied to utilize 
BR and PR/TT and other SIGINT authorities. As the illustration shows, the level of effort required by an analyst to establish RAS would normally be 
considered less than that required for FBI CT FISA or FAA 704/705b, but it is more than what is needed to utilize E.O. 12333, for example. 
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(U) Who can make a RAS determination? 

• (U//rOUO) Homeland Mission Coordinators (HMCs) 

• (U//rOUO) Chief of the CT Homeland Security Analysis Center 

• (U//rOUO) Deputy Chief of the CT Homeland Security Analysis 
Center 

(U) No one else can make this determination! 










frG//OI//Nr-) (OGC Attorney): The FISC states that the RAS decision is based on considerations of "reasonable and prudent persons." This does not, 
however, mean that anyone can approve an identifier for RAS. There are a select number of people within NSA who have been given the authority to 
approve identifiers for querying under these two authorities. Those individuals are called Homeland Mission Coordinators or HMCs. 

(TG//SI//Nr) (HMC Character): As was just mentioned, RAS determinations are typically made by specially trained personnel in the Office of 
Counterterrorism and its Extended Enterprise; these individuals are titled Homeland Mission Coordinators, typically abbreviated as HMCs. These 
individuals, like me, have been given special training on how to apply the RAS standard and how to apply it consistently. HMCs are specially trained 
individuals who have extensive experience working with this target set and who have extensive experience working with these authorities. The HMCs can 
take a RAS nomination, review the facts, and make a determination as to whether or not that particular identifier meets the RAS standard. 

(TS//SI//Nr) (HMC Character): According to the BR and PR/TT Orders, in addition to the HMCs, the Chief and Deputy Chief of the Counterterrorism 
Homeland Security Analysis Center are authorized to make a RAS determination; although, it is generally the HMCs who make the RAS determinations. To 
reemphasize, no one else is authorized to make RAS determinations according to the Orders. 
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(U) First Amendment Rights 

• Religion 
Speech 
The press 

• Peaceable assembly 

• To petition the government for redress of grievances 



tTIj//OI//Nr) (HMC Character): There are certain identifiers that require an extra RAS review/approval step. As you might imagine, those are the identifiers 
that are reasonably believed to be used by U.S. persons. Why does this matter? It matters because the U.S. Government is forbidden from regarding a 
U.S. person as associated with a Foreign Power solely because he or she is exercising his or her First Amendment rights. 



(TS//S I //NF) ( OGC Attorney): That's right. Any identifier believed to be used by a U.S. person must be forwarded to the OGC by a Homeland Mission 
Coordinator following his or her approval. An OGC attorney will review the RAS nomination, as well as the RAS decision made by the Homeland Mission 
Coordinator, and make a determination as to whether or not NSA is targeting that individual based solely on activities that are protected by the First 
Amendment to the Constitution. If there is any indication that the RAS is based solely on information or evidence protected somehow by the First 
Amendment, OGC will require additional information to support the RAS nomination. 

(TS//S I //Nr ) (HMC Character): If you are an analyst, should you abandon a RAS nomination if there is a potential First Amendment concern? Absolutely 
not. The presence of First Amendment evidence does not invalidate a RAS, it just cannot be the sole basis for a nomination. The OGC review is really 
transparent to the analyst, though it is a part of the process that you should be aware of. 



TOP GECRET//SF;^JOrORI-J 
Page 9 of 17 



TOP SECRET/ZSIyWOFORN 



DATE/PREPARER: 11/09/2010 SLS 



FRAME ID: 3070 



NEXT FRAME ID: 3080 



BACK FRAME ID: 3060 



ALT TAG: 



GRAPH IC/AV: 



Topic 

(U) Sources of Information 
Used to Jusitfy RAS 



Home 



Page Classification 

TO P 3ECRET//C0M I NT//N0F0RN 



Exit 



Glossary 



Screen Number 
8 of 13 



Back 



Next 



(U) What sources of information can be used to justify RAS? 



(TS//SI//NF) FISA Orders 

Existing FISA Orders 



TrS//Si//NF> Reports and/or RAW 
SIGINT 

SIGINT reports 

FISA surveillance data derived from other 
authorized targets 

Raw SIGINT (after a Reporting Source 
Validation Check) 
SIGDEV Work 
Other transcripts 



(TS//SI//NF) IC and Public Sector 

Federal Bureau of Investigation documents 
Central Intelligence Agency documents 
National Counterterrorism Center 
documents 

Documents from other U.S. Government 

Organizations 

Foreign Partner nations 

Public records available on the 

internet, newspapers, or other public 

resources 



(TS//SI//NF) (HMC Character): So now let's look at the type of evidence that can be used to justify RAS. NSA can use any information that is lawfully in our 
possession. A published SIGINT report describing the results of electronic surveillance of a target might be more reliable than say pocket litter found during 
a detainee's interrogation - but NSA can rely on any lawfully held evidence. The HMCs are responsible for assessing the quality and reliability of the 
evidence. 



(TO//S I //Nr ) (OGC Attorney): Sources that are often used to justify a RAS nomination include, but are not limited to: 
Existing FISA Orders 
• SIGINT reports 

FISA surveillance data derived from other authorized targets 

SIGINT traffic, as long as the submitting analyst has performed a Reporting Source Validation Check 
SIGDEV work (with verified sources), and 
Other transcripts 



(TS//S I //N P) (OGC Attorney): If an analyst/requestor uses unpublished query results in a RAS justification, and they classify the material appropriately as 



then that information will only be visible to those I 



lusers with 



I credentials, as confirmed 
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(TS//S I //NF) (OGC Attorney): The following IC and public sector (open source) sources are also examples of sources that are frequently used: 
Federal Bureau of Investigation (FBI) documents 
Central Intelligence Agency (CIA) documents 
The National Counterterrorism Center (NCTC) documents 
Documents from other U.S. Government Organizations 
Foreign Partner nations, and 

Public records available on the internet, newspapers, or other public resources. 
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• (TS//S I //NF) Supports the Homeland Defense Counterterrorism (CT) Mission. 

• (TS//S I //NF ) Provides the ability to request, justify, review, approve/disapprove RAS 
nominations/requests. 

• (TS//S I //Nr) Is the authoritative source for the list of RAS-approved identifiers and will export that list to 
other systems that require it. 

• (TS//S I //NF ) Provides metrics and other information to facilitate oversight review and report generation for 
the Department of Justice (DOJ) and the FISC. 

(U) Time Bounded Approvals 



(TG//S I //Nr ) (HMC Character): Remember from earlier in this module, we introduced the RAS process as a simple equation: identifier + link to Foreign 
Powers = RAS. Now you may be wondering how an identifier is nominated for RAS. NSA must demonstrate and document that ev^^^^^^r used to 
query the bulk metadata meets the RAS standard PRIOR to querying the BR and PR/TT bulk metadata repositories. NSA created the RAS 
identifier management tool, to streamline the adjudication of the RAS nomination statements and documentation of RAS determinations. 

(TS//S I //NF ) (HMC Character): Typically, an intellig|enc^nalvst will gather the necessary information and draft the nomination statement in IRONMAN 
articulating the RAS equation. An HMC, also usino^^^^^H will review the nomination statement and approve or disapprove the request. If the 
nomination statement is for a U.S. person, the^^^^^|tool includes functionality that allows the HMCs to forward such requests to OGC for the required 
First Amendment review. In either case, if the RAS nomination is approved, the identifier is now authorized for querying. 



(TG//O I //Nr ) (OGC Attorney): Through 
IRONMAN provides the ability to 
of RAS-approved identifiers, and 





NSA documents all RAS-approved identifiers, 
iTy, review, approve/disapprove RAS nominations 
lexports that list to other systems that require it. 




ithe rationale used to gain RAS approval, 
is therefore the authoritative source for the list 



(TS//S I //NF ) (OGC Attorney): It is important to remember that copies of the documents, such as court orders or reports, are required as part of the 
nomination process. The paper trail should enable an auditor from Department of Justice (DOJ) to clearly evaluate all of the evidence presented to support 
a RAS decision. 

lOP ShCKHT/73L'/KOrORN 
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(TS//S I //NF) (OGC Attorney): NSA has overseers, specifically the DOJ National Security Division attorneys, who examine the factual support for our RAS 
decision process. They take a look at any notes that the HMCs or someone within the NSA OGC may have included, and they decide whether or not we 
have properly applied the RAS standard to all of the identifiers that are used to query the bulk metadata. So it is critical that we take great car^hrauohout 
the process, gathering and presenting the evidence and applying the RAS standard in a consistent manner across all identifier nominations. ^^^^^H 
also provides metrics and other information to facilitate this oversight review and report generation for the DOJ and the FISC. 

(TS//S I //Nr) (OGC Attorney) The Court recognizes that occasionally, NSA may have information suggesting that a target may have used a particular 
identifier only for a limited time. In such cases, an HMC can determine that the RAS standard is met for the specifi^imeframe that the identifier was 
believed to be used by the target. Such instances are considered Time Bounded and are uniquely dealt with in ^^^^^H Analysts encountering targets 
under these circumstances should consult with an HMC on how to proceed. ^^^^^^ 
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(TS//S I //Nr) RAS determinations for foreign identifiers are legally effective for one 
year. NSA CT has implemented guidance that requires RAS review/re-approval every 
180 days. 

(TS//S I //NF) Although a RAS determination for an identifier reasonably believed to be 
used by a United States person is legally effective for 180 days, NSA CT has 
implemented guidance that requires RAS review/re-approval every 90 days. 

f TS//S I //NF ) After the sunset of an identifier's RAS approval - or anytime before ~ the 
identifier can be submitted for RAS revalidation through the same process. 



(TS//S I //N F) (HMC Character): RAS approvals have sunset or expiration dates which analysts must comply with. Currently a RAS approval on a foreign 
identifier, per the FISC, is legally valid for one year. However, NSA CT has taken a conservative approach and implemented guidance that mandates RAS 
review and re-approval every 180 days. Likewise, a RAS approval for an identifier believed to be used by a U.S. person has a legal lifespan of 180 days 
per the FISC, but NSA CT has implemented guidance requiring review and re-approval every 90 days. It is the analyst's responsibility to monitor the sunset 
dates and take appropriate actions before the RAS nomination expires. 

(TS//S I //NF ) (HMC Character): Any identifier can be resubmitted for revalidation at any time. Revalidations require proof of the same categories of 
information that was required for the original request. Revalidations should try to validate that the original evidence is still true by presenting any new 
documentation to demonstrate that the identifier is still associated with the Foreign Powers named in the Orders. It is up to the HMCs to make an informed 
revalidation, based on the totality of the evidence. If you are uncertain of your evidence, submit the nomination anyway and work with the HMCs through 
the process. 
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(U) Knowledge Check 

1 . ( TS//S I //Nr ) Why is the link between the target and the Foreign Powers an essential part of the RAS 
nomination? 

a) (TG//G I //Nr) It is a key component in reaching the 'probable cause' standard 

b) (TS//SI//NF) It is representative of the terrorist centric scope of the BR and PR/TT authorities 
as noted in the FISC Orders 

c) (U) Because it is required by USSID SP0018 and DoD 5240. 1-R 

d) (U) Because it is required in a DIRNSA Memo 

2. (TG//G I //Nr ) The RAG standard requires that what two facts are articulable? 

a) (TS//S I //Nr) The identifier can be tied to a terrorist target and that target can be tied to 

b) (TG//GI//NF) The identifier is not used by a U.G. person and they are engaged in terrorist 
activities 

c) (T3//3I//NF) The identifier can be tied to a ta rget and that target is affiliated with| 

d) ( I b//t3l//Nl-) I he query can be traced back to the analyst who submitted it and the identifier is 
associated with any terrorist group. 



(U) (HMC Character): Let's check what you remember from this topic! 



ANGWERG: 

Question 1 : (TG//G I //N F) Correct! The link between the target and the Foreign Powers is an essential part of the RAG nomination because it is 
representative of the terrorist centric scope of the BR and PR/TT authorities as noted in the FIGC Orders. 

(TG//GI//NF) Incorrect. The correct answer is b). The link between the target and the Foreign Powers is an essential part of the RAG nomination because it 
is representative of the terrorist centric scope of the BR and PR/TT authorities as noted in the FIGC Orders. 



Question 2: (TG//G I //Nr) Correct! The RAG standard requires that the following two facts are articulable: 

• The identifier can be tied to a terrorist target, and 

• That target can be tied to 

(TG//3I//NF) Incorrect. The correct answer is a). The RAG standard requires that the following two facts are articulable: 

• The identifier can be tied to a terrorist target, and 

• That target can be tied to ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^B 
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(U) Knowledge Check 

3. (TS//S I //NF) Who may make a RAS determination? 

a) (TS//S I //NF) A Homeland Mission Coordinator (HMC) or an attorney with the Department of 
Justice 

b) (TS//S I //Nr ) An HIVIC or other official named in the Orders 

c) (TG//G I //Nr) Any reasonable and prudent analyst (and OGC if identifier is believed to be used by 
a U.S. person) 

d) (TS//S I //NF) Only a judge from the FISC 

4. (TO//O I //Nr ) Which source of information may be used to justify RAS? 

a) (TS//S I //Nr) SIGINT reports 

b) ( TS//S I //NF) Open source information 

c) (TS//S I //NF) Second Party reports 

d) (TG//S I //Nr ) All of the above 

5. (TS//C I //Nr -) What additional requirement is needed for an identifier reasonably believed to be used by a 
U.S. person? 

a) ( TG//O I //Nr ) Must be reviewed by the Attorney Genera! 

b) ( TO//O I //Nr) Must be reviewed by the Chief of the Homeland Security Analysis Center 

c) (T S // SI //NF) Must be reviewed by OGC 

d) (TS//S I //Nr ) Two HMCs must agree on the RAS determination 



Question 3: ( TG//G I //Nr ) Correct! An HMC or other official named in the Orders may make a RAS determination. 
(TG//G I //Nr) Incorrect. The correct answer is b). An HMC or other official named in the Orders may make a RAS determination. 

Question 4: (TS//S I //N F) Correct! SIGINT reports, open source information, and Second Party reports may all be used to justify RAS. 

(TS//SI//NF) Incorrect. The correct answer is d). SIGINT reports, open source information, and Second Party reports may all be used to justify RAS. 

Question 5: (TS//S I //Nr ) Correct! If an identifier is reasonably believed to be used by a U.S. person, then it must be reviewed by OGC. 
(TS//S I //NF) Incorrect. The correct answer is c). If an identifier is reasonably believed to be used by a U.S. person, then it must be reviewed by OGC. 
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(U) Now that we have completed this part of your trip you should be able to: 

• (TS//S I //NF) Recognize the direct relationship between the Foreign Powers and 
establishing RAS 

. ( TS//S I //NF) Identify the key components of RAS and how it is applied to candidate 
identifiers 

• (TS//S I //Nr) Identify who can adjudicate and approve a RAS nomination 

• (TS//S I //MF ) Recognize the requirement associated with identifiers linked to U.S. 
persons - the OGC First Amendment Review 

• (TS//S I //NF) List common sources of information used to construct a RAS 
nomination statement 



(TS//SI//NF) (HMO Character): So remember, RAS nominations are approved by an HMC (or an official named in the Order) BEFORE queries can be 
made using a particular identifier within the BR or PR/TT metadata. 

(U) (OGC Attorney): Now that we have completed this part of the trip you should be able to: 

(TG//O I //Nr) Recognize the direct relationship between the Foreign Powers and establishing RAS 

( TS//S I //NF ) Identify the key components of RAS and how it is applied to candidate identifiers 

(TS//SI//NF) Identify who can adjudicate and approve a RAS nomination 

(TS//S I //NF) Recognize the requirement associated with identifiers linked to U.S. persons - the OGC First Amendment Review 
(TS//SI//NF) List common sources of information used to construct a RAS nomination statement 
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• (TS//SI//NF) Recognize the contact chaining restrictions for RAS-approved 
identifiers 

• (TS//SI//NF) Recognize what constitutes unique BR and PR/TT query results 

• (TS//SI//NF) Identify limitations that impact the access, sharing, dissemination, 
retention of BR and PR/TT query results 

• (TS//SI//NF) Recognize the BR and PR/TT dissemination tracking requirement 
the additional CT nexus requirement for U.S. person identifiers 


and 
and 



Derived From: NSA/CSSM 1-52 
Dated: 20070108 
Declassify On: 20360101 
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( TS//S I //NF ) (OGC Attorney): During this part of our trip we will identify the limitations regarding access, sharing, disseminating, and retaining of BR and 
PR/TT query results. 

(U) This module will enable you to: 

• ( TS//S I //N F) Distinguish between the analysts authorized to query BR and PR/TT metadata and those authorized to view query results 

• ( TS//S I //NF ) Recognize the contact chaining restrictions for RAS-approved identifiers 

• ( TS//S I //NF ) Recognize what constitutes unique BR and PR/TT query results 

• ( TS//S I //NF ) Identify limitations that impact the access, sharing, dissemination, and retention of BR and PR/TT query results 

• ( TS//S I //NF ) Recognize the BR and PR/TT dissemination tracking requirement and the additional CT nexus requirement for U.S. person identifiers 

( TS//S I //NF ) If you are a technical person, you might be asking yourself if this information is directly applicable to you and your team. Compliance with the 
FISC Orders could be jeopardized by inadvertent or unintended changes in the infrastructure maintained by technical personnel. Therefore, an 
understanding of the requirements outlined in the Orders is important in the event that any technical support functions (data access, presentation, 
underlying system support - both hardware and software, etc.) cause changes to the support infrastructure that would bring NSA's compliance with the BR 
and PR/TT Court Orders into question. 
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FRAME ID: 4020 


(TS//SI//NF) BR and PR/TT Credentials - who can query, who can view results 








(TS//SI//NF) Access to BR and PR/TT raw 








NEXT FRAME ID: 4025 


metadata and query results is restricted to tliose 
wlio have the required training and appropriate 
credentials 






BACK FRAME ID: 4010 












ALT TAG: 












GRAPHIC/AV: 

(U) Image of OGC Attorney, HMC 
Character, and SV Character sitting at a 
table 












(TS//SI//NF) (SV Character): Access to BR and PR/TT raw metadata and query results is restricted to those who have the required training and appropriate 
credentials. The OfTice of the Director of Compliance (ODOC) through the Signals Intelligence Directorate's Office of Oversight and Compliance (SV) 
controls access to the BR and PR/TT FISA metadata, ensuring that only those who have completed all of the required training and have been granted the 
appropriate credentials are permitted to touch the metadata. 




(TS//SI//NF) Within the analyst workforce, a distinction is made between individuals who are permittet^^uei^h^at^n^hose who are permitted only 
to view the query results. Individuals who are authorized to query BR and PF^TT metadata sets have ^^^^^^^^^^^^Icredentials. Division level 
management within a production center determines when query permissions will be granted to analysts based on a mission need, not solely on completion 
of BR and PR/TT FISA Training. Some technical personnel may also require query access, but their queries are for the purposes of data accuracy and 
integrity, not for target or intelligence analysis. Managers of technical personnel who require query permissions will make the determination in concert with 
their organization's compliance office, usually either SV or TV (the Technology Directorate's office of compliance). 
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FRAME ID: 4025 



NEXT FRAME ID: 4030 



(TS//SI//NF) How Do I Determine Who Has the Proper Credentials? 
(U) Type ^^^Ho access ^^^^^|and check credentials. 



BACK FRAME ID: 4020 



ALT TAG: 



GRAPHIC/AV: ^^^^ 
(U //FOUO ) View of ^^^^|or images 
pertinent to checking for credentials 



( TS//S I //NF ) (SV Character): So, how do you determine if an analyst or technical colleague has t he approp riate credentials? ^^^^^^is a tool that can 
hel^o^hecl^omeon^lse's credentials against your own. From your NSANet machine, type^H^I'n your web browser. This takes you to the 
^l^^^^^^^^^^^^^l Lookup Utility. Insert the sid of the analyst or technica^ei^oi^ouj^woif<ina ^ and hit search, the formal accesses you 
share in common are displayed. From that you can determine if they hold the^^^^^^^^^^^^^^^^|:redentials. If the utility is not functioning for 
some reason, you should contact SV4 to verify the individual's credentials before proceeding. 
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( TS//S I //NF ) The Court Orders require that when the metadata is queried for intelligence 
analysis purposes that an auditable record be generated. 

^^|audit log includes: 



( TS//S I //NF ) The 

• Query requests 

• User login 

• IP address 

• Date and time of the access 

(TS//S I //NF) What is the EAR and how does it function as a compliance safeguard? 



( TS//S I //NF ) (SV Character): The BR and PR/TT Court Orders require that an auditable record be generated whenever metadata is queried for intelligence 



and PR/TT metadata is queried in^^^^Han automatic audit log is generated to enable appropriate oversight of 
queries performed by both analysts and technical personnel and reviews the following on a periodic basis: 



analysis purposes. When thi 
these Authorities. SV audits 

• Query requests 

• User login 

• Internet Protocol (IP) address 

• Date and time of the access 

(TS//SI//NI^HM^i:haracter): While these audits are one way to verify that only RAS-approved identifiers are used as seeds to query the BR and PR/TT 
metadata, the analytic tool used to query this metadata, employs an Emphatic Access Restriction (EAR) software to provide reasonable 

assurance that only RAS-approved identifiers are queried by analysts. While the EAR is of great benefit for analysts, it should not lessen awareness and 
attention to detail while using the NSA tools and applications associated with BR and PR/TT. We'll discuss the EAR in greater detail later in this module. 



Comment [SLSl]: Noteforaudio recording, this 
is pronounced as a word^^^^^^^J 



Comment [SLS2]: Note for audio recording, this 
is pronounced as a word "EAR'' (not as letters) 
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(TS//SI//NF) Sourcing of BR and PR/TT Metadata Records 

(TS//SI//NF) Within NSA's source systems of record, BR and PR/TT metadata records 
tagged as to tlieir origin, wliicli allows for: 

• Determining if information is derived from the BR or PR/TT repository 

• Software and other management controls to function properly 


are 




(TS//SI//NF) (OGC Attorney): Another aspect of data access and governance is the requirement for the sourcing of BR and PRATT metadata records. As we 
mentioned in Module 2, the metadata must carry unique markings, or tags. These tags allow the analyst to determine if a particular piece of information is 
derived from either the BR or PR/TT repository. In addition, these markings enable the EAR software and other management controls to function properly. 



TOP SECRET//SI//NOFORN 
Page 7 of 39 



TOP SECRET//SI//NOFORN 



DATE/PREPARER: 11/23/2010 SLS 



FRAME ID: 4050 



NEXT FRAME ID: 4060 



BACK FRAME ID: 4040 



ALT TAG: 



GRAPHIC/AV: 



Topic 

(U) Knowledge 
Check 1 



Page Classification 

TOP SECRET//COM I NT//NOFORN 



Screen Number 
6 of 27 



Home Exit 
(U) Knowledge Checl< 1 



Glossary 



Back 



Next 



1 . ( TS//S I //NF ) Identify the individuals or groups below who are authorized to receive and view results of 
queries that contain BR and/or PR^^dat^Pjease check all that apply). 

a) Individuals witl^^^^^H^^Hcredentials ^^^^^^^^^^^ 
HMCs witfi ^^^^^^^^^^^md analysts with 
Technical personnelwith^^H credentials 

Your office chief and oversight personnel by virtue of their positional responsibility 
None of the above 



b) 
c) 

d) 
e) 



2. ( TS//S I //NF ) What should you do before sharing the results of a B^r PRATT query with a co-worker 
working on a target reasonably believed to be associated with the^^V 

Read your e-mail to see if your co-worker asked yoTnor the information 



a) 
b) 



d) 



Call one of the SOOs in the NSOC to find out if information about your target can be 
released to your co-worker 

Verify that the co-worl<er has the proper credentials to have access to BR and PR/TT 
information 

All of the above 



(U) (SV Character): Let's check in and make a few quick notes in our travel journal and see what we remember from this topic. 



ANSWERS: 

Question 1. ( TS//S I /NF ) Correct! a), b), and c) describe individuals and groups holding ^^^^^^^^|:redentials. 

( TS//S I /NF ) Incorrect. Positional authority does not supersede the requirement to have these specific credentials. Not all managers or SV personnel may 
require these credentials for their specific jobs. The correct answers are a), b), and c). 

Question 2. ( TS//S I /NF ) Correct! Before you share any BR or PR/TT query results with a co-worker, you must first verify that he or she has the proper 
credentials to have access to BR and PR/TT information. 

( TS//S I /NF ) Incorrect, The answer is c). Before you share any BR or PR/TT query results with a co-worker, you must first verify that he or she has the 
proper credentials to have access to BR and PR/TT information. 
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FRAME ID: 4060 
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(U) For the transcript paragraph spoken by 
the Technical Character, consider using a 
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for a brief period and then fades her out 
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(TS//SI//NF) Analyst Queries of the BR and PR/TT Metadata 

(U) Have RAS, will query? How? 

(TS//SI//NF) How do 1 recognize BR and or PR/TT results, and what are "unique" results? 
(U) Once 1 have results, how do 1 handle them? Are there any restrictions? 


(TS//SI//NF) (HMC Character): In this section of the module, we'll cover how analysts query the BR and PR/TT metadata. In addition, we'll go Into detail on 
what constitutes BR and PR/TT results and how to tell If they are unique. Since BR and PR/TT unique results may only be shared with Individuals who 
have the proper credentials, being able to Identify unique BR and PR/TT query results will help you comply with the sharing and handling restrictions. 

(TS//SI//NF) (Technical Character): While this section may appear to be more focused on analytic-specific tools, certain technical personnel also query 
these datasets to provide reasonable assurance of data Integrity or to make the metadata usable for Intelligence analysis. Therefore, technical personnel 
and their managers should also be aware of guidelines related to queries, handling instructions for query results, in any form, and the requirements related 
to sharing of unique query results, in any form. 
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( TS//S I //NF ) How are Analyst Queries of the BR and PR/TT Metadata Conducted? 

(TS//SI//NF ) Queries of BR and PR/TT metadata are conducted through ^^^^|the user 
interface to^^^^^^^As a default, queries are federated with data from other collection 
sources. 



Irrn Vqu will Ih^ri tifi 
^<^■atll'n:i <jiiv t^r rnuEbK ufthv uhd^rlyJng tUlfiff u^ficelatdd Willi 
Ihi.iB rjjUi r.n Jn tail r, wiiv ¥OtJ will 0* bOJWr ab\« 15 torilrOI 
Which dBEabases aire searched tr^yeuf query, 
ir, in ;34jilltirin 1r» f=;iOthJT (l^l^, ypu wii^ti lo worlcwrtth DQ^I 
f;oijrl-OF-dBrutj Dal?* 343urcesipl*NJ*l!CnSTHV|FI'3AeR), cnath 

ir ufivuiu. Iduvu ai6 bCiKH^i UrttHeCKCD dr^d CQntai:! h 
Homeland MlRjilon Cocirdlnflitcir. 3 JIA. a@3[-'C>l7e? 



«^ O 5PCMA bfddB 








«- LJI'IKamMcidn 




^ LJ Wirnim Mniln 











7 [Z] FISABR Mode 
[Z] FISABR 
[Z] E0 12333 



( TS//S I //NF ) (HMC 
the user interface to| 

wish to in clude BR or PR/TT metadata in their queries. If an analyst checks the "|FISABR Mode" or "P , 
^^^^|will perform a federated query. This means that in addition to either BR or PR/TT metadata 
additional collection authorities, depending on the analyst's credentials. Therefore, when performing^ 
potentially receive results from all of the above collection sources. Users of more recent versions of 
the query, and pick and choose amongst the collection sources that they would like to query. 



nee RAS approv ed, an ide ntifier can be used to query the BR and/or PR/TT metadata via authorized versions of 
When launching 



analysts with the appropriate BR or PR/TT credentials have the option to check a box inhe 

ENREGI STRY Mode" box when logging into 
^^^^BvNTalso query data collected under 

of the BR or PR/TT metadata, analysts will 
o have the option, however, to "unfederate" 




|omment [SLS3]: Note for audio recording, this 
should be pronounced as the word FISA tlten the 
letters B R, so simply "FISA B R" 



Comment [a4]: See Sereenshot 1. 
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(TS//SI//NF) (HMC Character): Once you are operating within the BR or PR/TT mode of ^^^^| remember that you may only use a RAS-approved 
identifier to query the metadata. A RAS-approved identifier that is used to initiate a query of BR or PR/TT metadata is referred to as a "seed" since it is 
being used to produce a "chain" of metadata contacts, known as contact chaining. 


(TS//SI//NF) ^^^^^mploys the EAR software to provide reasonable assurance that only RAS-approved identifiers are queried by analysts. Before 
executing a query on an identifier, the EAR verifies that the identifier is RAS-approved. If an analyst attempts to query a non-RAS-approved identifier while 
still in BR or PR/TT query mode, the EAR will provide reasonable assurance that no results are returned for that query; this includes data not derived from 
BR or PR/TT. This query will, howevei^^^ected in SV's auditing and a justification for the query attempt may be requested. If you are unsure whether 
an identifier is RAS-approved, use^^^^^Hto determine the identifier's approval status. 
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(TS//SI//NF) Contact Chaining with BR and PR/TT metadata 
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ALT TAG: 



GRAPHIC/AV: 

(U) Image of OGC Attorney, HMC 
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table 

(U) Look at ^^^|notes and match 
transcript to screen shots. 
( TS//S I //NF ) Create animation to explain 
the following: While the BR Order permits 
contact chaining for up to three hops, NSA 
has decided to limit contact chaining to only 
two hops away from the RAS-approved 
identifier without prior approval from your 
Division management to chain the third 
hop. Under PR/TT, the FISC limits the 
number of hops for internet 
communications to only two, and the hop 
counter will not permit these FISC- 
mandated levels to be exceeded 



( TS//S I //NF ) (HMC Character): Once the EAR verifies that the seed that the analyst has requested to query is RAS approved, it will allow the analyst to 
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"chain" on that identifier. In the BR and PR/TT Orders, the FISC sets limits on how e xtensive this chaining may be. We refer to this as the numb er of hops 
from a RAS-approved identifier. For example, let's say your target calls an associate ^^^^^^^^^^m^^That associate then calls several^^^B'n 

this example it is one hop from your RAS-ap proved id entifier to the associate and another hop from the associate to a recruit. In other words, the associate 
is a "first hop" contact of your target, and the ^^^|are "second hop" contacts. 



( TS//S I //NF ) (OGC Attorney): While the BR Order permits contact chaining for up to three hops, NSA has decided to limit contact chaining to only tw o hop: 
away from the RAS-approved identifier without prior approval from your Division management to chain the third hop. Under PR/TT, the FISC limits the 
number of hops for internet communications to only two. Technical controls will not permit these FISC-mandated hop levels to be exceeded. 



Comment [a5]: We can probably use some of the 
existing screenshots we made to also illustrate the 
hops. 



( TS//S I //NF ) (HMO Character): If another RAS-approved identifier is encountered within the authorized number of hops from the previous RAS-approved 
identifier, the number of hops resets to allow a contact chain to be generated out the authorized number of hops from the newly encountered RAS- 
approved identifier. 
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( TS//S I //NF ) What is a Query Result and how do I know if it is a BR or PR/TT Query 
Result? 

( TS//S I //NF ) Query Result: Queries produce results in the form of a contact cliain 
presented in^^Jormat; each chain is comprised of individual contacts derived from data 
returned from the multiple collection sources queried. Each contact/line within a chain 
represents an individual result. ^ 



[ Comment [a6]; This is illustrated by screenshot 2 ) 



( TS//S I //NF ) (HMC Character): When you query a RAS-approved Identifier in ^^^^^n BR or PR/TT modes, ^^^^^ill return a ^B^''^' usually 
referred to as a chain, which is made up of the individual first hop contacts of the seed. Bearing in mind the hop restrictions just discussed, analysts may do 
further chaining on those contacts. Each of these contacts, or line within the chain, represents an individual result . Remember, unless you choose to 
unfederate your query as we described eariier, these results may have been obtained under a variety of collection authorities. 

( TS//S I //NF ) It is possible to determine the collection source or sources of each result within the chain by examining the Producer Designator Digraph 
(PDDOySIGINT Activity Designator (SIGAD) and c ollection source (s) at the end , of the line. 



Comment [a7]: This is illustrated by screenshot 2 



( TS//S I //NF ) If at least one source of a result is BR or PR/TT metadata, the classification at the beginning of the line will contain the ph rases FISABR or 
PR/TT, respectively. In addition, in the source information at the end of the line, the SIGAD ^^^^B^^^^^^^^B^^^^^^^^fcR data can be 

recognized by SIGADs beginning with 

after October found ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^HFor a 

comprehensive listing of all the BR and PR/TT SIGADs as well as information on PR/TT data collected prior to November of 2009, contact your 



Comment [SLS8]: Note for audio recording, this 
should be pronounced as a word "SIGAD" ( not 
spelled out in letters as S I G A D) 



Comment [a9]: I really think we need some 
For PR/TT, dataj pictures to illustrate. 
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organization's management or subject matter expert. 

(TO//OI//fijr) Since it is possible that one communication event will be collected under multiple collection authorities (and multiple collection sources), not all 
of the results will be unique to one collection authority (or collection source). Keep in mind that the classification at the beginning of each result only 
indicates the hiahest level classification of that result, and does not necessarily reflect whether a result was uniaue to one collection authoritv for collection 






|Comment [SLSIO]: Note for audio recording, 


^^^^^^^^^^^^^^MHere are examples of results originating from multiple collection sources. None of these results are considered BR- or PR/IT- 


the acronym PDDG should be spelled out m letters 
'T D D G" followed by the word "SIGAD" -- so this 
phrase will be recorded as "Producer Designator 
Digraph, or PDDG or SIGAD" 

Comment [all]: Screenshot 
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( TS//S I //NF ) What is a BR- or PR/TT-Unique Query Result? 



Next 



(U) (Insert image of OGC Attorney and HMC Character sitting at a table discussing the 
talking points below shown on a white board) 

( TS//S I //NF ) BR- or PRm-"unique" query results are those contacts within a chain 
solely derived from the BR or PR/TT metadata and not duplicated in the results originating 
from any other authorities. 



(TS//S I //NF) (HMC Character): In the examples we just discussed, none of the results were unique to any one collection authority. Frequently, however, 
you'll find that some of the results within the chain are unique to one particular collection authority. A BR- or PR/TT-unique query result is any piece of 
information that NSA would not have had but for the BR or PR/TT metadata from which it was drawn. In other words, BR or PR/TT was the ONLY source of 
that individual contact/query result. 



(TS//S I //NF) Here are some examples: example A is "E.O. 12333-unique," while B is "PR/TT-unique," and C is "BR-unique." 



[ Comment [al2]: Again show previous examples. ] 



(TS//S I //NF) Sharing restrictions in the FISC Orders only apply to unique BR or PR/TT query results. If query results are derived from multiple sources anc 
are not unique to BR and PR/TT alone, the rules governing the other collection authority would apply. We will discuss these sharing and handling 
restrictions in greater depth shortly. 



Comment [SLS13]: Note for audio rceording; 
we will want some time in between saying example 
A is "E.O. 12333-unique," and wliile B is 
"PIVTT-unique," and and C is "BR-unique." 

to allow learner to look at the examples. Please 
allow some "quiet" space that can be duplicated 
to the amount of time needed. THANKS! © 
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(TS//SI//NF) BR or PR/TT Query Results Not Just a Line Within a Cliain 
(TS//SI//NF) Examples of BR and/or PR/TT Query Results include: 






NEXT FRAME ID: 4105 


• A specific identifier 

• "Identifier A was in contact witli Identifier B" 

• A .cm! file (i.e. tlie entire contact cliain/result set) that contains BR or PR/TT query 




BACK FRAME ID: 4090 


results 

• A written or electronic depiction of a chain (i.e., the .cml file itself) or the analysis or 
partial analysis of a chain that includes BR or PR/TT results 

• A compilation or summary of first- and second-level contacts from a RAS-approved 
seed 

• A draft or a finished but not yet disseminated report 

• Any other BR or PR/TT information returned following a RAS-approved federated 
query 




ALT TAG: 




GF5APHIC/AV: 





TOP SECRET//SI//NOFORN 
Page 18 of 39 



TOP SECRET//SI//NOFORN 



( TS//S I //NF ) (OGC Attorney): Before we discuss sharing and handling restrictions of BR- and PR/TT-unique query results, it is impor tant to understand that 
a BR or PR/TT query result is not just a line within the chain that is presented to you after you run a BR or PR/TT query in ^^^^|Any information that 
you derive, extract, or manipulate from that particular line in the chain becomes a BR or PR/TT result. Given that a source of the result is derived from BR 
or PR/TT metadata, any adaptation of that result, including information provided orally or in writing, even a tip or a lead, remains a BR or PR/TT query 
result. 

( TS//S I //NF ) (OGC Attorney): In addition, other examples of items that have been deemed to be BR and PR/TT query results include: 

• A specific identifier 

• "Identifier A was in contact with Identifier B" 

• A ^^Tile (for example the entire contact chain/res ult se t) that contains BR or PR/TT query results 

• A written or electronic depiction of a chain (like the ^|file jitself) or the analysis or partial analysis of a chain that includes BR or PR/TT resu lts 

• A compilation or summary of first- and second-level contacts of a RAS-approved seed 

• A draft or a finished but not yet disseminated report 

• Any other BR or PR/TT information returned following a RAS-approved federated query 



Comment [SLS14]: Note for audio recording, 
tiic SMEs would like for this to be pronouneed "the 
^^^^ffile" - 1 know this might sound a little odd 
sinee we don't say things like "the dot p d f file" but 
just trust ine on this one because we had a 5 ininute 
argument about it in a SME meeting. UGH! 
HI 
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(TS//SI//NF) (HMC Character): So, for example, if you run a BR or PR/TT query on a particular RAS-approved e-mail identifier and it returns information 
that depicts identifier A, the RAS-approved seed, was in direct contact with identifier B and the source of the metadata is BR or PR/TT, then just the fact 
that identifier A is communicating with identifier B is considered a BR or PR/TT query result. 




(TS//SI//NF) (HMC Character): In addition, any summary of that information would also be a BR or PR/TT query result. So, if you knew that identifier A 
belonged to Joe and identifier B belonged to Sam, and the fact of that contact was derived from BR or PR/TT metadata, if you communicate orally or in 
writing that Joe talked to Sam, even if you don't include the actual e-mail account or telephone numbers that were used to communicate, this is still a BR or 
PR/TT query result. 




(TS//SI//NF) (OGC Attorney): Remember, if these results are determined to be BR- or PR/TT-UNIQUE, they are subject to sharinq and handling 
restrictions. 
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( TS//S I //NF ) Sharing and Handling Restrictions of BR- or PR/TT-Unique Query 
Results 

( TS//S I //NF ) Examples of handling restrictions for BR and PR/TT unique query 
results: 

• Any document, .cml, or other file containing BR- or PR/TT-unique information may 
only be stored on the analyst's personal folders, or an access-controlled, shared 
location 

• Query results canr^^^^^^^^u|y system where the results would be shared with 
individuals without 

• BR- or PR/TT-unique results may not be quene^i^ool^/vhere user queries are 
visible to other analysts (who may not have ^^^^^^^^^^ or can be 

manipulated by behind the scenes analytics ^ 



Comment [al5]: There is no such Ust of tools 
that are ok/ not ok to query, btw. 



(TS//SI//NF) These restrictions apply to information that is SOLELY unique to BR and 
PR/TT and do WOT apply to information which is WOT unique to BR or PR/TT! 



( TS//S I //NF ) (OGC Attorney): Remember, BR- or PR/TT-unique query results are those contacts within a chain solely derived from the BR or PR/TT 
metadata and not duplicated in the results originating from any other authorities. Any oral or written depiction, manipulation, or summary containing that 
information is also a unique query result. Until they are officially disseminated, BR- or PR/TT-unique results may only be shared with individuals who hold 
the proper credentials to receive or view BR or PR/TT information. The requirement is imposed because of the special handling restrictions that we will 
discuss later in this Module. Without the proper training, the FISC-imposed handling restrictions may not be followed. 

( TS//S I //NF ) (HMC Character) Unless these unique results have been disseminated, such BR- or PR/TT-uniqu^nformation may only be shared with 
Individuals who have the proper credentials to receive or view BR or PR/TT information. Remember, use ^^^|to deter mine a user's credentials. This 

means: 

« Any dnriimpnt.^B i n i illici file containing BR- or PR/TT-unique information may only be stored on the analyst's personal folders, or an access-^ comment [SLS17]: Please say 



Comment [SLS^l^Jotc for audio recording, 
this is pronounced 
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controlled, shared location that is accessible to only BR and PR/TT cleared personnel. 
Query results cannot be put into any system where the results would be shared with individuals without] 

BR- or PR/TT-unique results may not be queried in tools where user queries are visible to other analysts (who may not havel 

can be manipulated by behind the scenes analytics. If you have questions regarding which tools are acceptable to further research query results, 
please contact your management or technical director. 



( TS//S I //NF ) (SV Character) However, as we've discussed, not all BR or PR/TT results are unique. If a query result indicates it was derived from another 
collection source in addition to BR or PR/TT, the rules governing the other collection authority would apply to the handling and sharing of that query result. 
For example, this result came from both BR and E.O. 12333 collection; therefore, because it is not unique to BR information, it would be ok to inform non- 
BR cleared individuals of the fact of this communication, as well as task, query, and report this information according to standard E.O. 12333 guidelines. 

( TS//S I //NF ) (SV Character) In summary, if a query result has multiple collection authorities, analysts should source and/or report the non-BR or PR/TT 
version of that query result according to the rules governing the other authority. But if it is unique to either the BR or PR/TT authority then it is a unique 
query result with all of the applicable BR and PR/TT restrictions placed on it. In both cases, however, analysts should not share the actual chain containing 
BR or PR/TT results with analysts who do not have the credentials to receive or view B^i^Rn"T information. In such an instance, if it is necessary to 
share the chain, analysts should re-run the query in the non-BR or non-PR/TT areas of ^^^^ l and share that .cml. 
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(U) Retention of Metadata and Query Results 

(TS//SI//NF) NSA must destroy BR and PR/TT metadata no later than five years (60 
months) after initial collection 

(TS//SI//NF) The FISC has not imposed any destruction requirement on BR or PR/TT 
query results 




(TS//SI//NF) (OGC Attorney): The Court Orders mandate destruction of the metadata five years or 60 months after initial collection. NSA destroys the BR 
and PR/TT metadata no later than five years after collection. There are no exceptions to this requirement when it comes to the bulk metadata. 

(TS//SI//NF) (HMC Character): The destruction requirement applies to the bulk metadata; it does not apply to query results that have been generated as a 
result of queries of RAS-approved identifiers. Once we have queried the metadata we have selected metadata, or query results, and the 60-month cutoff 
does not apply. 
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(U) Knowledge Check 2 

3. ( TS//S I //NF ) Please complete the following sentence. The Emphatic Access Restriction (EAR) 



a) create^j^utomatlc auditable record to allo w for oversight of these authorities. 

b) alerts ^^^^^|when an Individual without ^^^^^M^^^^Hattempts to conduct a 
query. 

c) forwards the query request to the HMC for approval. ^^^^^^^ 

d) prohibits non-RAS-approved identifiers from being queried in 

e) None of the above. 

4. ( TS//S I //NF ) Assuming that the following answers descrlb^jniqu^B^oi^R^T query results, which of the 
following could be shared with co-workers who do not have^^^^^^^^^^^| 

a) Having a fellow analyst review the draft of a report that contains PR/TT-derived information 

b) A summary of direct or in direct contacts of a RAS- approved i dentifier 

your manager that ^^^^^^^^^^^^|contacted as 

noted in the PR/TT query you recently performed 

d) E-mailing an electronic depiction of a BR or PR/TT contact chain or a pattern 

e) None of the above. 

5. (TS//S I //NF) TRUE or FALSE: If a query result indicates that the source of information is both Executive 
Order 12333 collection and PR/TT collection, then the analyst must handle the E.O. 12333 result according 
to the PR/TT rules. 

a) True 

b) False 



(U) (HMC Character): Let's make a few notes In our travel journal and check to see what you remember from this topic! 
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ANSWERS: 

Question 3. ( TS//S I //NF ) Correct! The EAR prohibits non-RAS-approved identifiers from being queried in 
( TS//S I //NF ) Incorrect. The correct answer is d). The EAR prohibits non-RAS-approved identifiers from being queried in 



Question 4. ( TS//S I //NF ) Correct! None of the examples listed should be shared with anyone outside of 
( TS//S I //NF ) Incorrect. The correct answer is e). None of the examples listed should be shared with anyone outside of 




channels. 



Question 5. ( TS//S I //NF ) Correct! If a PR/TT query result can also be sourced to Executive Order 12333, then the information is considered E.O. 12333 
collection and follows the E.O. 12333 processes and procedures. 

( TS//S I //NF ) Incorrect. If a PR/TT query result can also be sourced to Executive Order 12333, then the information is considered E.O. 12333 collection and 
follows the E.O. 12333 processes and procedures. 



TOP SECRET//SI//NOFORN 
Page 25 of 39 



TOP SECRET//SI//NOFORN 



DATE/PREPARER: 11/23/2010 SLS 



Topic 

(U) Knowledge Check 2 



Home 



Page Classification 

TOP SECRET//COM I NT//NOFORN 



Screen Number 
18 of 27 



Exit 



Glossary 



Back 



Next 



FRAI\/1E ID: 4135 



NEXT FRAME ID: 4140 



BACK FRAME ID: 4130 



ALT TAG: 



GRAPHIC/AV: 



(No audio or transcript on this page) 




(U) Knowledge Check 2 

6 . (TO//O I / /HR-)t^^^^^^^^^^^Jis your RAS-approved identifie r, and he e-mails 
who then e-mails ^^^^^^^^^^^^^^Hwho then e-mails 

how many hopsis^^^^^^^^^^^^^^Hfrom your RAS-approved 

identifier? Are you allowed to chain that far in the PR/TT mode of^^^^^ 

a) 4 hops, no, unless one of the contacts between^^^^|and RAS 

approved. 

b) 3 hops, no (unless one of the contacts between] 
RAS approved). 

c) 4 hops, yes. 

d) 3 hops, no. 

e) 2 hops, yes. 

7. ( TS//S I //NF ) If Badguyl's identifier is RAS-approved, and he calls Associatel, who then calls 
Unknownguy, who then calls Unknownguy2, how many hops^^^J^^nguy2 from your RAS-approved 



identifier? Are you allowed to chain that far in the BR mode of| 



a) 4 hops, no, unless one of the contacts between badguyl and unknownguy2 is RAS 
approved. 

b) 3 hops, yes (with management approval). 

c) 4 hops, yes. 

d) 3 hops, no. 

e) 2 hops, yes (with management approval). 
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ANSWERS: 

Question 6. ( TS//S I //NF ) Correct! The _ 
far unless one of the contacts between 
( TS//S I //NF ) Incorrect. The correct answer is b). I he 
permitted to chain this far unless one of the contacts' 

Question 7. ( TS//S I //NF ) Correct! The^^^^^f 
approval. ^^^^^^^1 
( TS//S I //NF ) Incorrect. The correct answer is b). The 
management approval. \ 




is 3 hops from the RAS-appr oved identifier. You would not be permitted to chain this 
^is RAS approved. 
hopsJromJh^RA^^DDTOve^dentifier. You would not be 
^^^^^^^^^^^^^^^|is RAS approved. 

s 3 hops from the RAS-approved identifier. You are permitted to chain this far with management 

^^^^^^^Hs 3 hops from the RAS-approved identifier. You are permitted to chain this far with 
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(TS//SI//NF) Dissemination of BR- and PR/TT-Derived Information 

(TS//SI//NF) Dissemination of BR and PR/TT results is distributing information to external 
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(TS//SI//NF) Topics covered: 

• Information of foreign intelligence value which contains only foreign person information 
that IS NOT unique to BR or PR/TT 

• Information on U.S. persons (minimized) or foreign target activity unique to BR or PR/TT 
metadata 

• Information on U.S. persons (unminimized) unique to BR or PR/TT 
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(TS//SI//NF) (OGC Attorney): Now let's focus our attention on the dissemination of BR and PR/TT results. We define dissemination of BR and PR/TT 
results as distributing information to external customers in any form to include oral or written form. Let's say you perform a BR or PR/TT query using a 
RAS-approved identifier, and the query returns good foreign intelligence information based on unique BR or PR/TT metadata that you would like to report 
to Intelligence Community customers. What should you do? In this topic we will discuss to what extent we can use standard processes and procedures for 
the dissemination of this information and to what extent we must use special processes and procedures for the dissemination of this special foreign 
intelligence information. Given the sensitive nature of this Program, you will not be surprised to hear that there are special rules that apply to the 
dissemination of this information. 
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(TS//S I //NF) Information Derived Exclusively from BR or PR/TT - Additional Requirements 



(TS//S I //NF) Standard reporting practices and policies (including sourcing requirements and 
procedures and USSID SP0018 minimization) apply to BR and PR/TT query results 

(TS//S I //NF) Two additional, BR- and PR/TT-specific requirements: 



Tine Counterterrorism (CT) nexus requirement applies to BR- and PR/TT-derived 
unminimized U.S. person information, but does not apply to BR- or PR/TT-derived non- 
U.S. person information or BR- or PR/TT-derived minimized U.S. person information 
The dissemination tracking requirement applies to all BR- and PR/TT-derived 
information 



(TS//S I //NF) (OGC Attorney): First of all, every disseminated report from NSA must include sourcing information so that we know where the information 

came from, as well as follow all USSID SP0018 minimization requirements and procedures. For BR- and PR/TT-derived information, the analyst or r eport^ Comment [SLSIS]: update 7/13/11 from the 
needs to make sure that the information included in that report is properly sourced to the appropriate BR or PR/TT authority. 



SMEs: Please reeord at USSID 18 (do not say SPEW 
or SPOW, just -USSID 18" 



(TS//S I //NF) In addition, the Court Orders for both the BR and PR/TT authorities have imposed two unique, stringent requirements with respect to 
disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus requirement, and the second is the dissemination tracking 
requirement. 
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(TS//S I //NF) The CT Nexus Requirement 



( TS//S I //NF) Prior to the dissemination of BR- or PR/TT-derived unminimized U.S. person 
information outside of NSA, one of tlie designated approval autliorities must determine: 

(a) that the U.S. person information is related to CT information, and 

(b) that the U.S. person information is necessary to understand the CT information 
or to assess its importance 



(TS//S I //NF) (OGC Attorney): The CT nexus requirement applies only to U.S. person information. If you run a query and the information returned is all 
foreign person information, then the CT nexus requirement does not apply to this situation. However, if your query results include U.S. person information 
derived from BR or PR/TT and you want to disseminate that information to an external customer, such as the FBI, then this requirement must be met prior 
to dissemination, in any form. Traditionally, under USSID SP0018! , if there is a piece of unminimized U.S. person information that you would like to 
disseminate, one of the designated approval authorities (to be covered on the next screen) needs to determine that the information is necessary to 
understand the foreign intelligence in that particular intelligence report before the information can be released. For BR and PR/TT, the requirement is 
slightly different. 

(TS//S I //NF) (OGC Attorney): With respect to the BR and PR/TT authorities, the unminimized U.S. person information not only has to relate to and be 
necessary to understand the foreign intelligence information in the report, but it has to relate to and be necessary to understand the Counterterrorism 
information. 



Comment [SLS19]: UPDATE 7/13/1 1 from the 
SMEs: Please reeord at USSID 18 (do not say SPEW 
orSPOW, just "USSID 18" 
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(TS//S I //NF) (HMC Character): Recall the RAS process and how you derived this information. The identifier you used to generate this information was 
approved based upon the RAS standard. It was found to be an identifier reasonably believed to be used by someone 1"^ 



(TS//S I //NF) (HMC Character): It might seem as though the information would most certainly be counterterrorism-related since, due to the RAS approval 
process, you wouldn't have this U.S. person information from a query of BR or PR/TT if it weren't related to counterterrorism. In the majority of cases, it will 
be counterterrorism-related; however, the nature of the counterterrorism target is that it often overlaps with several other areas that include 
counternarcotics, counterintelligence, money laundering, document forging, people and weapons trafficking, and other topics that are not CT-centric. Thus, 
due to the fact that these authorities provide NSA access to a high volume of U.S. person information for counterterrorism purposes, the Court Order 
requires an explicit finding that the information is in fact related to counterterrorism prior to dissemination. Therefore, one of the approved decision makers 
must document the finding using the proper terminology. It must state that the information is related to counterterrorism and that it is necessary to 
understand the counterterrorism information. 



l-(OGC Attorney): While the USSID SP0018 process is the most familiar method of governing the dissemination of unminimized U.S. person 
information obtained from traditional SIGINT means, the CT nexus requirement is an additional protection for U.S. person information being disseminated 
when the BR or PR/TT authorities, and metadata obtained by virtue of those authorities, is the source of the information. The FISC wants to ensure that the 
authorities are being used for counterterrorism purposes as intended, so consider the CT nexus requirement a step above justifying a foreign intelligence 
requirement. 
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( TS//S I //NF ) Only those in the following NSA positions have the authority to approve the 
dissemination of BR- or PR/TT-derived U.S. person(s) information: 

(U) USSID SP0018 

• (U //FOUO ) The Chief and Deputy Chief of Information Sharing Services 

• (U //FOUO ) The Senior Operations Officers (SOOs) of the National Security 
Operations Center (NSOC) 

• (U //FOUO ) The Director and Deputy Director of the Signals Intelligence Directorate 

• (U //FOUO ) The Director and Deputy Director of NSA 

(U) This approval authority cannot be delegated to anyone else! 



(T S//S I //NF ) (OGC Attorney): Certain positions are authorized to validate the CT nexus requirement, as we just discussed, and approve the dissemination 
of U.S. person{s) information that w/e obtain from these two authorities. 

( TS//S I //NF ) (OGC Attorney): Recall from your USSID SP0018 training, there are certain positions at NSA which have the authority to approve the 
dissemination of information that would identify a U.S. person either by name or by context. Those positions are listed in USSID SP0018 and include the 
Chief and Deputy Chief of the Information Sharing Services Office, the Senior Operations Officers (SOO) within the National Security Operations Center 
(NSOC), the Director and Deputy Director of the Signals Intelligence Directorate (SID), and in some cases they include the Director and Deputy Director o 
NSA. 

( TS//S I //NF ) (HMC Character): The list of positions which can approve the dissemination of unminimized U.S. person information derived from unique BR 
and PR/TT query results is the same as those named in USSID SP0018. 



Comment [SLS20]: Note for audio recording, 
tiiis is pronounced as a word "SOO" (rhymes with 
"/7eu'", but docs not rltymc with "^eiv a dress") 



Comment [SLS21]: Note for audio recording, 
this is pronounced "N sock" 
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( TS//S I //NF ) (OGC Attorney): It is important to note that the authority to approve the dissemination of U.S. person information cannot be delegated. This 
responsibility is assigned only to the positions named in the BR and PR/TT Court Orders. Let's say, for example, that the Chief and Deputy Chief of 
Information Sharing Services Office, the two individuals who on a normal daily basis would be making the decision, are both on vacation on the same day. 
In this instance, someone else within their office may be the acting chief on that day; however, the acting chief cannot make the decision to disseminate 
U.S. person information. 

( TS//S I //NF ) (HMC Character): Under these circumstances, if information about a U.S. person must be disseminated on that day, then you should send 
your dissemination request to one of the other positions named in the Orders. This would logically be the NSOC SOO. 

( TS//S I //NF ) (OGC Attorney): With respect to non-U. S. person information, standard NSA practices and policies (such as proper sourcing information) 

apply- 
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(U) Dissemination Tracl^ing 



( TS//S I //NF ) NSA must report to the FISC every 30 days the number of instances since the 
preceding report in which NSA disseminated BR- or PR/TT-derived information, in any 
form (oral, written, formal, or informal), with anyone outside of NSA 

(U) For more information, please contact ^^^^^^^^^^^H 



( TS//S I //NF ) (OGC Attorney): The other requirement, which applies to both U.S. person information as well as foreign person information, is the 
dissemination tracking requirement regarding the dissemination of BR- and PR/TT-derived information. The Orders require NSA to track and report to the 
FISC every instance in which NSA disseminates any information derived from either of these two authorities. 



( TS//S I //NF ) (HMC Character): This refers to information disseminated in a formal report as well as information disseminated informally such as written or 
oral collaboration with the FBI. We need to count every instance in which we take a piece of information derived from either of these two authorities and 
disseminate it outside of NSA. 



( TS//S I //NF ) (HMC Character): Normally an NSA product report is the record of a formal dissemination. In the context of the BR and PR/TT Programs, an 
official RFI response or Analyst Collaboration Record will also be viewed as dissemination. Because this FISC requirement goes beyond the more standard 
NSA procedures, additional diligence must be given to this requirement. NSA is required to report disseminations formal or informal to the FISC every 30 
days. 
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(U) Post-Dissemination Restrictions? No, Restrictions lifted once Disseminated 

( TS//S I //NF ) Once approved for dissemination, BR- or PR/TT-derived information can be 
used witliin NSA for any lawful purpose, and the sharing restrictions no longer apply 
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(U) Possible cutaway images may include: 
• Image that portrays the lifting of the 
sharing restriction once information 

is approved for dissemination 

( TS//S I //NF ) (OGC Attorney): Once BR and PR/TT information has been disseminated (such as in a product report, RFI, or briefing), generally speaking, 
there are no follow-on restrictions that either NSA or our customers need to follow regarding the sharing or dissemination of that information contained in 
the report. The Orders do not impose any restrictions on the use of formally reported information from the BR or PR/TT authorities; therefore, this 
information can be used for any lawful purpose. 



( TS//S I //NF ) If BR- or PR/TT-derived information is disseminated outside of NSA, then the restrictions on internal sharing of that same information at NSA 



no longer apply. For exa 
other tools such as the f 



jsseminated can be shared outside of 



Ichannels, and the identifiers can be used in 
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(U) Knowledge Check 3 

8. (TS//SI//NF) Identify the additional requirements reqardinq the dissemination of unminimized U.S. person 
information derived from BR or PR/TT information: 

a. The Counterterrorism nexus check 

b. The Counterintelligence nexus check 

c. The dissemination tracking requirement 

d. The sourcing requirement 

e. Both a) and c) 

9. (TS//SI//NF) TRUE or FALSE: the dissemination tracking requirement applies to only U.S. person BR- or 
PR/TT-derived information. 

a. TRUE 

b. FALSE 


NtA 1 rKAIVIt lU. 4Z 1 U 
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(U) (OGC Attorney): Before we move on to the next part of our trip, let's make a few notes in our travel journal. 


ANSWERS: 

Question 8. (TS//SI//NF) Correct! The Court Orders for both the BR and PRATT authorities have imposed two unique requirements with respect to 
disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus check (which applies only to U.S. person information), and 
the second is the dissemination tracking requirement. 

(TS//SI//NF) Incorrect, the correct answer is e). The Court Orders for both the BR and PR/TT authorities have imposed two unique requirements with 
respect to disseminating information from these authorities. The first is the Counterterrorism, or CT, nexus check (which applies only to U.S. person 
information), and the second is the dissemination tracking requirement. 

Question 9. (TS//SI//NF) Correct! The dissemination tracking requirement applies to both U.S. person and non-U. S. person BR- and PR/TT-derived 
information. 

(TS//SI//NF) Incorrect. The dissemination tracking requirement applies to both U.S. person and non-U. S. person BR- and PR/TT-derived information. 


TOP SECRET//SI//NOFORN 
Page 36 of 39 





TOP SECRET//SI//NOFORN 



DATE/PREPARER: 11/23/2010 SLS 



FRAME ID: 4210 



NEXT FRAME ID: 4220 



BACK FRAME ID: 4200 



ALT TAG: 



GRAPHIC/AV: 



(No audio or transcript on this page) 



Topic 

Knowledge 
Check 3 



Page Classification 

TOP SECRET//COM I NT//NOFORN 



Screen Number 
26 of 27 



Home Exit 
(U) Knowledge Checl< 3 



Glossary 



Back 



Next 



refers to the distribution of 



10. ( TS//S I //NF ) For the purpose of the BR and PFVTT Programs 

information to customers in any form. is the provision of BR and PR/TT FISA query results with 

others inside of NSA authorized to receive BR and PR/TT query results. 

a) Dissemination, Distribution 

b) Sharing, Dissemination 

c) Dissemination, Shiaring 

d) Sharing, Distributing 

1 1 . ( TS//S I //NF ) Which one of the following NSA positions does not have the authority to approve the 
dissemination of BR- or PR/TT-derived unminimized U.S. person information? 

a) The SOOs in the NSOC 

b) The Director and Deputy Director of the Signals Intelligence Directorate 

c) The Director and Deputy Director of NSA 

d) The Office of General Counsel (OGC) 

e) The Chief and Deputy Chief of Information Sharing Services 



ANSWERS: 

Question 10. ( TS//S I //NF ) Correct! Dissemination is the more formal distribution of information to customers in either oral or written form. Shiaring is the 
provision of BR and PR/TT FISA query results with others inside of NSA authorized to receive BR and PR/TT query results. 

( TS//S I //NF ) Incorrect. The correct answer is c) Dissemination is the more formal distribution of information to external customers in either oral or written 
form. Sharing is the provision of BR and PR/TT FISA query results with others inside of NSA authorized to receive BR and PR/TT query results. 

Question 1 1 . (TS//S I //NF) Correct! The answer is d) The OGC does not have the authority to approve the dissemination of BR- or PR/TT-derived unminized 
U.S. person information. 

(TS//S I //NF) Incorrect. The answer is d) The OGC does not have the authority to approve the dissemination of BR- or PR/TT-derived unminized U.S. 
person information. 
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(U) Now that we have completed this part of your trip you should be able to: 

• (TS//SI//NF) Distinguish between the analysts authorized to query BR and PR/TT 
metadata and those authorized to view query results 

• (TS//SI//NF) Recognize the contact chaining restrictions for RAS-approved 
identifiers 

• (TS//SI//NF) Recognize what constitutes unique BR and PR/TT query results 

• (TS//SI//NF) Identify limitations that impact access, sharing, dissemination and 
retention of BR and PR/TT query results 

• (TS//SI//NF) Recognize the BR and PR/TT dissemination tracking requirement and 
the additional CT nexus requirement for U.S. person identifiers 
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(TS//SI//NF) (OGC Attorney): Remember, you are responsible for ensuring that the recipient of query results is authorized to receive these results. Also, 
you must be mindful of the special restrictions for dissemination, either oral or written, of the BR- and PR/TT-derived information. 

(U) (OGC Attorney): Now that we have completed this part of the trip you should be able to: 

• (TS//SI//NF) Distinguish between the analysts authorized to query BR and PR/TT metadata and those authorized to view query results 

• (TS//SI//NF) Recognize the contact chaining restrictions for RAS-approved identifiers 

• (TS//SI//NF) Recognize what constitutes unique BR and PR/TT query results 

• (TS//SI//NF) Identify limitations that impact access, sharing, dissemination, and retention of BR and PR/TT query results 

• (TS//SI//NF) Recognize the BR and PR/TT dissemination tracking requirement and the additional CT nexus requirement for U.S. person identifiers 
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(U) The Analytical and Technical Work Roles 
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(U) This module will enable you to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 
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• (U) Identify how the authorities impact interactions with other roles and the data 
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(U) (Technical Character): During this part of our trip we will compare and contrast the analytical and technical work roles and provide you with a basic 
knowledge of the two distinct areas. This will serve as an introduction to the more role-specific module you will complete later. 


(U) This module will enable you to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 
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(U) The Analytical Work Role 

(TS//SI//NF) The Analytical Work Role includes these primary functions: 

• HMC 

• Those who conduct intelligence analysis queries 

• Those who can view and disseminate the results of intelligence analysis queries 


(TS//SI//NF) (HMC Character): The analytical work role includes three primary functions: Homeland Mission Coordinators (HMC), those who can conduct 
intelligence analysis queries, and those who can view and disseminate the results of intelligence analysis queries. 

(TS//SI//NF) Homeland Mission Coordinators, or HMCs, review and approve the RAS nominations. The analysts and HMCs work through the RAS approval 
process together to get the identifiers RAS-approved. 

(TS//SI//NF) Recall from the last module that not al^nalvst^r^emiitted to conduct contact chaining queries. Those who are permitted to conduct 
queries of the bulk metadata have been gr^nte^^^^^^H^^^^^^credentials. Those who are permitted to view and disseminate query results, but 
not conduct queries, have been granted |^|^^^^^^^^|crBdential^ 
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(U) The Technical Work Role 

( TS//S I //NF ) The Technical Work Role is m ade up of tw o main functions: 

• Support to Collection and Metadata 

• Support to Storage, Presentation, and Maintenance 
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( TS//S I //NF ) (Technical Character): The work performed by technical personnel in support of the Bulk Metadata Programs assists everyone working in 
support of these programs to maintain complia nce with ap plicable legal documents and relevant authorities. Within the technical roles, there are two main 
areas of responsibility: collection and metadata ^^^^^|and the storage, presentation, and maintenance of the metadata. 



(TS//S I //NF) Some high-level examples of how key organizations support collection and metadata ^^^^^|include: 

Ito gain access to BR and PR/TT metadata. 




|develops protocol processing software that supports the collection and metadata! 



and standardization. 



• Mission Capabilities (TD) integrates the BR and PR/TT protocol processing software into the larger exploitation systems. 

( TS//S I //NF ) ^^^^^^^^^^^and Mission Capabilities also support the storage, presentation, and maintenance aspects of the Bulk Metadata 
Programs, and some high-level examples include: 

• Mission Capabilities manages the BR and PR/TT repositories, as well as prepares the metadata for the analysts to use. 

• ^^^^^^^^^^Bp''<^v'<^^^ reasonable assurance that the data is normalized and presented in a usable format and provides support to 
intelligence analysts. 
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(U) Authoriz ations for Technical Personnel 

Create, test, and implemenHool^^Tiake this 
data easier for analytic personnel to use (TS/^^^^^^^^^^^B 

Validate Jjia^afefliiaM^DDropriately control analyst's access 

o Validation 

o Defeat of collection 

o Processing 

o Analysis of high-volume identifiers 

o Maintenance of records to demonstrate compliance 



Perform processes to make the data usable 



( TS//S I //NF ) (Technical Character): As we have discussed throughout the course, the sensitivity of the data drives many of the policies and restrictions that 
control access to the BR and PR/TT bulk metadata. However, because of the different roles and responsibilities of analytical and technical personnel, both 
have different authorizations to touch the metadata. Recall from Module 1 we defined "touching the data" as any form of data handling that creates an 
opportunity for a violation of the FISC Orders to occur. These activities may include data acquisition, modifying/preparing the data, querying, viewing results 
of the queries, and even oversight and compliance functions. 

( TS//S I //NF ) (HMC Character): Analytic personnel have authorization to touch the metadata to perform intelligence analysis. Analyst actions, such as 
querying the metadata for intelligence analysis purposes, must be done in a controlled way via tools designed to limit intelligence analysis access to RAS- 
approved identifiers and to the appropriate number of hops. Using these tools also provides reasonable assurance that these queries are tracked and 
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Technical Personnel Info (audio file name OVSC 1205 M5 5040 T): 

( TS//S I //NF ) (Technical Cliaracter): Tecinnical personnel create, test, and implement tools to make this data easier for analytic personnel to use, while 
validating that safeguards appropriately control analysts' access to the bulk metadata. Additionally, technical personnel may access the metadata to 
perform those processes needed to make the metadata usable for intellioenc^na lysis. These processes may include metadata validation; the defeat 
of the collection, processing, or analysis of metadata associated with identifiers; and the maintenance of records to demonstrate 

compliance with the terms of the authority. 



(TS//S I //NF^ ^rder to do this work effectively, technical personnel are allowed to access the metadata using identifiers that are not RAS-approve^r^e 
case of ^^^^^^B identifiers, technical personnel may use non-RAS-approved identifiers to query the metadata to confirm if the identifier is a^^B 
^^^^identifier and thus should not be included for target analysis. They may then share the identifier and the fact that it is a^^^^^^|identifier 

with authorized personnel. However, no other information resulting from such queries can be used for intelligence analysis purposes. 



( TS//S I //NF ) Technica^er^onnel must take great care with their responsibilities because they may be accessing the data through tools that do not have 
safeguards, such as that impose restrictions and minimize the chances of a violation of the FISC Orders. As a result, we need to maintain 

boundaries between technical and analytical personnel, and be crystal clear as to the circumstances under which the two groups can interact. 
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(U) (Begin with image of analytical and Technical Character sitting at a table, then provide a close up of the 
Technical Character) 

( TS//S I //NF ) All interactions must be based on RAS-approved identifiers and those results found within the 
number of hops authorized for intelligence analysis purposes 
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( TS//S I //NF ) (Technical Character): As we just discussed, analytical and technical personnel have different authorizations to touch this metadata. 
Because of these differe nt authorizatio ns, we must be careful when the two types of personnel are interacting with regard to this metadata. Specifically, 
outside of the sharing of identifiers for defeat purposes, technical personnel should only be providing analytical personnel information 

under certain conditions. 

( TS//S I //NF ) (HMC C haracter): Som etimes, when analyzing the results of intelligence analysis queries, one or more of the specific results may seem out 
of the ordinary. Is it a identifier that was overlooked? Is the identifier misnormalized? Is there something that just seems out of place? Or 

perhaps there is a particular data field in your results that you don't understand. In such instances, intelligence analysts may require assistance from 
certain technical personnel responsible for data integrity functions. 

( TS//S I //NF ) (Technical Character): In these instances, technical personnel may assist authorized intelligence analysts, but any and all assistance must 
be based on RAS-approved identifiers and those results found within the number of hops authorized for intelligence analysis purposes. Essentially, 
when providing information to analytical personnel in these circumstances, the technical personnel must abide by the rules for the analytical personnel. 

( TS//S I //NF ) (Technical Character): In the end, all personnel have a vested interest and shared responsibility in ensuring that only the most accurate 
intelligence information is reported to customers, while abiding by the policies and requirements in place for this metadata. 
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(U) Knowledge Check 

1 . ( TS//S I //NF ) TRUE or FALSE: Technical personnel and analytic work roles have the same authorization to 
touch the bulk metadata. 

a) TRUE 

b) FALSE 

2. ( TS//S I //NF ) The Analytic Work Role includes these functions: intelligence analysts who query the data, 
intelligence analysts who can view the results of intelligence analysis queries, and . 

a) Mission Capabilities (TD) 

b) 

c) Homeland Mission Coordinators (HMC) 

3. ( TS//S I //NF ) The Technical Work Roles are comprised of two general areas of responsibility including 1 ) 
and 2) _. 

a) 1) collection and metadata ^^^^^|2) reviewing RAS nominations 

b) 1) collection of content, 2) storage, presentation, and maintenance of the metadata 

c) 1) reviewing RAS nominations, 2) working with the telecommunications partners 

^^^H^) storage, presentation, and maintenance of the 



d) 1) collection and metadata 
metadata 



(U) (Technical Character): Let's make a few notes in our travel journal and see what we remember from this topic. 
ANSWERS: 

Question 1 . ( TS//S I //NF ) Correct! The answer is b) FALSE. Technical personnel have authority to make the metadata usable for intelligence analysis, while 
analytical personnel can only touch the bulk metadata for intelligence analysis purposes using RAS-approved identifiers within the authorized number of 
hops. 

( TS//S I //NF ) Incorrect. The correct answer is b) FALSE. Technical personnel have authority to make the metadata usable for intelligence analysis, while 
analytical personnel can only touch the bulk metadata for intelligence analysis purposes using RAS-approved identifiers within the authorized number of 
hops. 
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Question 2. ( TS//S I //NF ) Correct! The correct answer is c). Tine Analytical Work Role includes analysts and Homeland Mission Coordinators (HMC). 
( TS//S I //NF ) Incorrect. The correct answer is c). The Analytical Work Role includes analysts and Homeland Mission Coordinators (HMC). 

Question 3.- (T0//S I //Nr) Right! The correct answer is d). The Technical Work Roles are comprised of two general areas of support including collection and 
metadata ^^^^^as well as storage, presentation, and maintenance of the metadata. 

(TS//SI//N F) Incorrec t. The correct answer is d). The Technical Work Roles are comprised of two general areas of support including collection and 
metadata ^^^^Mas well as storage, presentation, and maintenance of the metadata. 
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(U) Knowledge Check 

4. (TS//SI//NF) staff have access to the bulk metadata in order to prepare the metadata for 
the analysts to use. 

a) ^^^^^^H 

b) Mission Capabilities (TD) 

c) Analytical 

d) Office of General Counsel (OGC) 

5. (TS//SI//NF) If an intelligence analyst seeks assistance from technical personnel, technical personnel 


ALT TAG: 


a) can query the metadata to confirm the analyst's results and point out potentially noteworthy 
contacts at the third or fourth hop 


GRAPH IC/AV: 


b) should explain that they are unable to assist in any way, except to identify^^^^^^^| 

identifiers 

c) may offer assistance, but must be cautious that any results shared or discussed are 
based on a RAS-approved identifiers and those results that fall within the number of hops 
authorized for intelligence analysis purposes 

d) should provide whatever assistance Is needed, but make a note of it in case anyone in 
management has questions later 

e) should decline to assist because technical personnel should not assist intelligence analysts 


(No audio or transcript on tinis page) 


Question 4. (TS//SI//NF) Correct! Mission Capabilities staff has access to the bulk metadata in order to prepare the metadata for the analysts to use. 
(TS//SI//NF) Incorrect. The correct answer Is b). Mission Capabilities staff has access to the bulk metadata in order to prepare the metadata for the analysts 
to use. 

Question 5. (TS//SI//NF) Correct! If an intelligence analyst seeks assistance from technical personnel, technical personnel may offer assistance, but 
must be cautious that any results shared or discussed are based on RAS-approved identifiers and those results that fall within the number of hops 
authorized for intelligence analysis purposes. 

(TS//SI//NF) Incorrect. The correct answer is c). If an intelligence analyst seeks assistance from technical personnel, technical personnel may offer 
assistance, but must be cautious that any results shared or discussed are based on RAS-approved identifiers and those results that fall within the 
number of hops authorized for intelligence analysis purposes. 
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(U) Summary 

(U) Now that you have completed this module you should be able to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) identify how the authorities impact interactions with other roles and the data 
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(U) (Technical Character): Now that we have completed this part of our road trip, you should be able to: 

• (U) Compare and contrast the analytical and technical work roles 

• (U) Identify analytical and technical personnel's authorization to touch the data 

• (U) Identify how the authorities impact interactions with other roles and the data 

(TS//SI//NF) (Technical Character): Now that you are aware of the various roles that support the BR and PR/TT Programs you will move on to your role- 
specific module that will go into additional detail on topics relevant to your responsibilities. 
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(U) Module 6 

(U) The Analytical Work Role 

(U) This module will enable you to: 

• (TS//S I //NF) Identify how BR and PR/TT fit into the analytic workflow 

• (TS//S I //NF) Recognize how BR and PR/TT authorities apply to real-life scenarios 
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( TS//S I //NF ) (OGC Attorney): Throughout the first five modules of our course, we have discussed the BR and PR/TT Orders and the policies and 
procedures NSA has implemented to provide reasonable assurance of compliance with the Orders. We also have looked at the community of people and 
the work roles that are involved across the Enterprise to support that aspect of the mission. 



( TS//S I //NF ) (HMO Character): This part of our trip is designed specifically for anyone working in an analytical role, or supervising staff in an analytical role, 
in support of the BR and PR/TT Bulk Metadata Programs. In particular we will discuss facets of BR and PR/TT that are of interest to analysts and HMCs. 
This module will enable you to: 

• ( TS//S I //NF ) Identify how BR and PR/TT fit into the analytic workflow 

» ( TS//S I //NF -) Recognize how BR and PR/TT authorities apply to real-life scenarios 
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( TS//S I //NF ) BR and PR/TT Programs enable NSA to fill collection gaps left by our other 
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( TS//S I //NF ) (Display introductory 
images/graphics pertinent to the Zazi 
story). 

( TS//S I //NF ) Graphic showing the portfolio 
of CT authorities with BR and PR/TT 
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arrest. 

( TS//S I //NF ) (HMC Character): In Module 1, we mentioned that in order to gain comprehensive insight into a target's activities, it is often necessary to 
leverage multiple authorities and tools. CT targets have maintained an ongoing desire to conduct attacks within the United States. Given the unique U.S.- 
focus of the BR and PR/TT Programs, NSA is able to fill collection gaps left by our other authorities. 

( TS//S I //NF ) To illustrate how these various authorities can complement each other to fill critical gaps, as well as to show how BR and PR/TT fit into the 
analytic workflow, we'll step through the example of Najibullah Zazi and the New York subway plot. 
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( TS//S I //NF ) (HMC Character ): ^^^^^^^^^^^^^^^^^^^^B, CT an alysts discovered a Pakistan-based email address associated with^^^^B 
operations ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^I^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^B the analysts 
tasked the address to FAA 702 and reviewed the subsequent traffic on a regular basis. 

( TS//S I //NF ) In Fall of 2009, one particular piece of content collection obtained from FAA 702 revealed an email exchange between a Pakistan-based target 
and an unknown individual suggesting that an unspecified terrorist operation was about to take place. Within this email, the analyst also discovered what ^ 
appeared to be a U.S. -based phone number that was missing the country ^ode^ 
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NSA reported the suspicious activity and minimized U.S. phone number in a standard EGFRAM. After 
receiving the unminimized U.S. phone number through NSA's Identity Release process, the FBI learned that the user of the unknown email address and _ 
owner of the phone number was a Colorado-based individual named Najibullah Zazi. FBI immediately started an investigation into Zazi's activities^ 
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(TS//SI//NF) 




lU.S. person Najibullah Zazi is the user oft 

\According to SIGINT reporting 
I a Pal<istan-basecl al-Qa'ida (AQ) facilitator, 

Ireceived an email from Naiibullah Zazi on 6 




Dhone number. 



( TS//SI//NF ) (HMC Character): Simultaneously, to gain a fuller picture of Zazi's contacts, an NSA CT analyst submitted a RAS-approval reques t to an HMC 
on Zazi's phone number and email address. Recall from Module 3 that, in order to meet the RAS standard, an identifier must be tied to specific^^l 
^^^^^^^^^^^^^^^^^^1 In this case, the analyst met the RAS standar^^asin^h^ustification on the fact that Zazi was in direct 
communication with the Pakistan-based email address used by a member of ^^^^^^^^^^^^^Because Zazi is a U.S. person, after the RAS 
requests on Zazi's identifiers were reviewed by an HMC, they were then sent to OGC, who performed a First Amendment review and gave the final 
japproval^ 



I Comment [a3]: Graphic of RAS template ] 



( TS//S I //NF ) When considering RAS, analysts should remember to include just the basic facts needed with supporting documentation, as was done in the 
Zazi case, and not clutter the justification with excess information or documentation. 
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( TS//S I //NF ) (HMC Character): After the RAS requests were approved, using the BR and PR/TT modes of ^^^^|0T analysts began running federated 
metadata queries on the approved identifiers , as we discussed in Module 4. Th e analyst querying Zazij^Colorad^hone number discovered that around 
the time that Zazi exchanged emails with the he had also contacte^^^^^^^^^^B}hone numbers. Using the 

guidance that we discussed in Module 4, the analyst determined that Zazi's contacts with these ^^^^^Bininln i i n unique to BR metadata. Based on 

this uniqueness, the analyst began drafting a report in accordance with the dissemination guideli we reviewed in Module 4. Before the report was 

released, the Chief of S12 determined that the report met the CT Nexus criteria and approved its release^ 



Comment [a5]: Use one of screenshots showing 
what a ehain/query looks like 



(TS//S I //NF) Remember, even "fact of statements describing what BR- or PR/TT-unique data was discovered are considered "query results" under FISC 
guidelines an d must be handled in accordance with the Court Orders. However, once formally disseminated to customers, it no longer requires the 

Iprotection and is treated as normal SIGINT analysis, as is the case with the example we have just described. 
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(U) Knowledge Checl< 

1. ( TS//S I //NF ) In the Zazi scenario, analysts used E.G. 12333 and FAA 702 collection to support F^S. 
Which source{s) can be used to support FJAS? 

a) (U) FBI reporting 

b) (U) Open source information 

c) ( TS//S I //NF ) NSA FISA collection 

d) (U) All the sources above can be used 

2. ( TS//S I //NF ) Why was the RAS request for Zazi sent to OGC for a First Amendment review? 

a) (TS//S I //NF) All RAS requests go to OGC for a First Amendment review 

b) (TS//S I //NF ) Zazi is a U.S. person 

c) (TS//S I //NF ) Zazi is a member of al-Qa'ida or an associated terrorist group 

d) ( TS//S I //NF ) The RAS determination was a close call 



GRAPHIC/AV: 



(U) (HMC Character): Let's make a few notes in our travel journal and check to see what you remember from this topic! 



Question 1. (U //FOUO ) Correct! Any information that is law/fully in our possession may be used to support a RAS determination. 

(U //FOUO ) Incorrect, the correct answer is d). Any information that is lawfully in our possession may be used to support a RAS determination. 

Question 2. (U //FOUO ) Correct! A First Amendment review is only necessary when the identifier is believed to belong to a U.S. person. 

(U //FOUO ) Incorrect, the correct answer is b). A First Amendment review is only necessary when the identifier is believed to belong to a U.S. person. 
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3) (TS//SI//NF) In this scenario, information was discovered that was unique to the BR authority. If that same 
information had also been discovered in E.G. 12333 collection, a CT Nexus determination would still need to 
be made in order to disseminate that information because the information was in the BR repository. 


NEXT FRAME ID: 6100 


a) (U)True 

b) (U) False 








4) (TS//SI//NF) Why are students without^^^^^^f allowed to learn that ZazI had contact with other New 
York numbers? ^^^^^^^^^ 
a) (TS//SI//NF) That information is not specific enough to qualify as 


BACK FRAME ID: 6080 


ALT TAG: 


b) (TS//SI//NF) The information is over one year old 

c) (TS//SI//NF) The information has been previously disseminated outside of NSA 




d) (TS//SI//NF) It is being shared for training purposes 




GF5APHIC/AV: 








(No audio or transcript on this page) 


Question 3. (TS//SI//NF) Correct! If the same information is discovered through another source, neither the BR nor PFWTT rules and requirements apply. 
(TS//SI//NF) Incorrect. The correct answer is b) (False). Neither the BR nor PR/TT rules and requirements apply if the same information is discovered 
through another source. 


Question 4. (TS//SI//NF) Correct! The information can be disclosed to those without because it has previously been disseminated outside 


of NSA. ^^^^^^ 

(TS//SI//NF) Incorrect. The correct answer is c). The information can be disclosed to those without ^^^^^^^^|only because it has previously been 


disseminated outside of NSA. 
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(U) Practice Scenario 1 

(TS//SI//NF) You are a cleared analyst who, through PR/TT metadata analysis of seeds associated 
with a high value CT target, has identified a PR/TT-unique direct contact - email address^^^^^^^^^^^^^B 

believed to be used by someone ii^^mei^^^i^To^ure whether the identifier warrants further development as 
a target, but to find out you place in a tasking database to enable content collection from 
E.O. 12333 sources. This tasking oataDas^^wiael^ivailSjIe to all intelligence analysts in the SIGINT Production 
Chain. For this reason, you note in the comments field that this identifier was discovered through metadata analysis 
and is believed to be a direct contact of the high value CT target, but you deliberately avoid identifying the PR/TT 
metadata as the source of the identifier. Are your actions in compliance with the terms of the PR/TT Orders? 

(U) Please select the your answer: 

a) (TS//SI//NF) Yes, because you did not include the reference to PR/TT. 

b) (TS//SI//NF) No, because you failed to mark the source of the identifier as PR/TT metadata. 

c) (TS//SI//NF) Yes, because the results will be governed under E.O. 12333 rules and procedures. 

d) (TS//SI//NF) No, because you have shared a PR/TT-unique q uer^jesul^ith a wide audience 
of intelligence analysts, many of whom do not hold current ^^^^^^^^Hcredentials. 


(U) (HMC Character): Now let's practice what we have learned using a real-life scenario. Carefully read the scenario and then select the best answer. 


ANSWER: 

a) (TS//SI//NF) Incorrect. The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current ^^^^^^^^^redentials. 

b) (TS//SI//NF) Incorrect. The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current ^^^^^^^Hcredentials. 

c) (TS//SI//NF) Incorrect. The correct answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of intelligence 
analysts, many of whom do not hold current credentials. 

d) (TS//SI//NF) Correct! The right answer is d). No, because you have shared a PR/TT-unique query result with a wide audience of 
intelligence analysts, many of whom do not hold current ^^^^^^^^Icredentials. 
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(U//FOUO) You should now be able to: 






NEXT FRAME ID: 6110 


• (TS//SI//NF) Identify how BR and PR/TT fit into the analytic workflow 

• (TS//SI//NF) Practice applying BR and PR/TT authorities in real-life scenarios 




BACK FRAME ID: 6090 


(TS//SI//NF) If you have questions or wish to find out more, please contact your^^^^^^ 


leaned manager or any of the following BR or PR/TT points of contact: 




ALT TAG: _ 












GRAPHIC/AV: 


OGC email alias: DL gc_ops 

OGC Phone:^^^^^|or g63-3121(s) 








OGC website: go GC 








HMCs email alias: DL CT_HMC 








SID Oversight and Compliance email alias: DL SV42_all 




(U//FOUO) (HMC Character): Now that we have completed this part of our road trip, you should be able to: 

• (TS//SI//NF) Identify how BR and PR/TT fit into the analytic workflow 

• (TS//SI//NF) Practice applying BR and PR/TT authorities in a real-life scenario 




(TS//SI//NF) (HMC Character): You are encouraged to reach out to your^^^^^^^^|cleared manager or any of the points of contact listed here if you 
have any questions or if you want to find out more. Please remember that it is critical to our mission that we are 100% compliant with the requirements in 
the Court Orders especially with regards to collaborating, sharing, and disseminating this data through the course of your analysis work. You may review 
this course at any time and seek guidance from any of the points of contact listed here. 
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(U) PLEASE READ: Important Assessment Information 

• (U) You will view the questions in a separate Assessment Questions Document 

• (U) You will enter your responses in a separate QuestionMark online answer sheet 

• (U) You will have only one attempt to successfully complete the assessment 

• (U) Allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U) To Complete the Assessment: 

• (U) Click the link to open the Assessment Questions Document| 



(U) Go to the VUport SumTotal Content Player page, click on the Assessment link, and follow the 
instructions to complete the required exam 



Comment [SLS6]: Please make this a link that 
will open the Assessment Question pdf for 
Analytical Personnel (we will aetually conneet the 
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(U //FOUO ) (OGC Attorney): The final part of your trip will be to successfully complete the assessment for the course. Please be aware that for the 
assessment you will view the questions in a .pdf file and enter your responses in a separate QuestionMark online answer sheet. Please be sure that you 
open the .pdf with the questions first before opening the QuestionMark online answer sheet. You will have one attempt to complete the assessment. Please 
allow yourself sufficient time (approximately 30 minutes) to complete the assessment. 

(U //FOUO ) Please click the Assessment Questions Document link to open the .pdf question file and keep the window open. Then go to the VUport 
SumTotal Content Player page, click on the Assessment link on the left, and follow the instructions to complete the required exam. 
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(U) Module 6 

(U) The Technical Work Role 

(U) Tliis module will enable you to: 

• - (TO//G I //rjF) - Identify the various technical roles that support the BR and PR/TT Bulk 
Metadata Programs 

• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission 
systems and data flows 

• ( TS//S I //NF) P ractice applying BR and PR/TT authorities in real-life scenarios 
applicable to technical personnel 



(TS//S I //Nr) (OGC Attorney): During this part of our trip, we discuss several topics of particular interest to those of you in technical roles, or supervising 
staff in a technical role, supporting the BR and PR/TT Bulk Metadata Programs. It is important for you to remember that the essential support you provide 
enables all of the roles to perform their BR- and PR/TT-related work in compliance with applicable legal documents and relevant authorities. As we 
discussed in Module 5, because of this great responsibility, technical personnel have been given tremendous access to touch the data in order to make it 
available and usable for the analysts. 

(TS//S I //NF ) (Technical Character): In this module we are going to discuss the authorizations, roles, and responsibilities of the Technical Personnel. This 
module will enable you to: 

• (TS//S I //NF) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 
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• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission systems and data flows 

• (TO//O I //Nr) Practice applying BR and PR/TT authorities in real-life scenarios applicable to technical personnel 
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(TS//SI//NF) (Technical Character): In Module 5, we explained there are two major areas where technical support Is provide^or the BR and PRATT Bulk 
Metadata Programs. The first Is the group of technical personnel who are responsible for the collection and metadata ^^^^H Process. The second Is the 


group responsible for storage, presentation, and maintenance of the BR and PR/TT metadata. In the next few screens, we will describe In more detail these 
two main areas of responsibility. 
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(U) Collection and Metadata Extraction Support 




(U) Collection and Metadata 




(U) Mission Capabilities 



(U// FOUO) (Technical Character): Let's examine more closely the work roles resDonaibl^QiJi^Qllectim^njyjiet^^ 

category of technical staff currently includes the technical professionals in NSA's^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^Hand Mission 
Capabilities staff within the Technology Directorate (TD) organizations. As we proceed through this module you will find out more about the roles in each of 
these three organizations. 

(TO//G I //Nr) Note that in addition to these key roles, there are other technical roles that are important to the implementation of these programs. These roles 
include individuals involved in the acquisition, processing, presentation, storage, retention, and support to operations which are authorized under the BR 
and PR/TT Orders. 
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(TS//SI/mr) Some o^h^uleUha^ppMo^M 

• Acquire data^^^^^^^^^^^^^^^^^authorized by the FISC 

• Identi^^lUi^^^^^^^^^^^^ 

• ^^^^^^^^^^^^^^^^^^B^ promptly 

• Changes to systems require approval by the Chief of S3 
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• Validate that only properly| 




re m 




(TS//S I //hJF) Some of the roles that 

• Provide reasonable assurance that all 
FISC Orders. 

• Validate that only properly ^^^^H metadata is forwarded to the 
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• All metadata remains identifiable as PRATT 

• ^^^^^^^^^^^^^^^^^^^s promptly destroyed 





"(TSTTSIt^^ 



^i^^^^^^^^^^^^^^^^^^^ ^^^^^^g^^^^^^^hnoloqv Pirectorate (TP) are to provide reasonable assura nce that: 
All of the metadata remains identifiable as PR/TT data 



TOP SECRET//SI//I'JOrORI'J 
Page 9 of 30 



TOP SECRET//SI//NOFORJ-J 








(TO//GI//Nr) This staff will rarely come in contact with human intelligible PR/TT metadata. Scroll over the logo to find out more about Mission Capabilities. 


Scroll over text box for Mission Caoe 
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(U) Knowledge Check 1 

(U) Match the organization to its corresponding roles and responsibilities: 

is responsible for developing the 



a) (U) Mission Capabilities 

b) ^^^^^^^^H 

d) (U) Homeland Mission Coordinators 



jtafHn 

a) (U) IVIission Capabilities 

b) 



is responsible for integrating the PR/TTi 

Including conducting related testing prior to system 




d) (U) Homeland Mission Coordinators 
3. (TS//S I //Nr) Staff in is responsible for| 




a) (U) Mission Capabilities 
b) 
c) 

d) (U) Homeland Mission Coordinators 




(U) (Technical Character): Let's make a few notes in our travel journal and check to see what you remember from this topic! 
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(U) Storage, Presentation, and Maintenance of the IVIetadata 



(U) Storage, Presentation, and Maintenance of the Metadata 



(U) Mission Capabilities 




(TO//O I //Nr) (Technical Character): Now let's discuss the work roles responsible for the storage, presentation, and 
metadata. This category of technical staff currently includes the technical professionals in Mission Capabilities and 



e BR and PR/TT 



TOP GECRET//SLWJOFOrJJ 
Page 13 of 30 



TOP SECRET/ySLyNOFORI-J 



DATE/PREPARER: SLS 



Topic 

(U) Storage, Presentation, and 
Maintenance of the Metadata by TP 



Home 



Page Classification 

TOP 

SECRET//COM I NT//NOrORN 



Screen Number 
9 of 20 



Exit 



Glossary 



Back 



Next 



FRAI\/1E ID: 7090 



(U) storage, Presentation, and Maintenance of the IVIetadata 



NEXT FRAME ID: 7100 



BACK FRAME ID: 7080 



ALT TAG: (U) Mission Capabilities Logo 



GRAPHIC/AV: 

(U) Have the TD loa^n^nf^o)^DDear 

grey the 
boxes while the Mission Capabilities info is 
displayed. 

td-logo-small.gif (or td-logo-med.gif) 



(U) Storage, Presentation, and Maintenance of the Metadata 



(U) Mission Capabilities 




(TS//SI//NF) Mission Capabilities is 
responsible for: 

• Developing, maintaining, and operating 
repositories that store and present BR and 
PR/TT metadata 




(TG//SI//NF) S ome of the rules that apply to Mission Capabilities: 

• Metadata must be maintained in secure NSA repositories 

• Data must be identifiable as BR or PR/TT 

• Implement technical controls to prevent unauthorized access 

• Restrict intelligence analysis queries to RAS-approved identifiers (e.g. the EAR) 

• Ensure intelligence analysis queries remain within authorized number of hops 

• Create auditable records of all intelligence analysis queries 

• Destroy all metadata before the end of the five year authorized retention period (no 
exceptions!) 

• Changes to systems must be certified by the TD Compliance Office before 
implementation 

• Automated queries are prohibited without approval 
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(TS//S I //NF) (Technical Character): You will recall that Mission Capabilities supports collection and metadata ^^^^^|and other branches of Mission 
Capabilities support storage, presentation, and maintenance of the metadata. For th^atter the staff is typically database management and user interface 
professionals who are responsible for developing, maintaining, and operating the ^^^^Jthat store and present BR and PR/TT metadata, as well as 



(TG//O I //Nr ) Some of the rules that apply to Mission Capabilities include: 

• Metadata must be maintained in secure NSA repositories 

• Data items must be identifiable as BR or PR/TT metadata 

• Implement technical controls to prevent unauthorized access 

• Implement technical controls to restrict intelligence analysis queries to RAS-approved identifiers {e.g. the EAR) 

• Implement technical controls to provide reasonable assurance that the results of intelligence analysis queries remain within the authorized number 
of hops 

• Create auditable records of all intelligence analysis queries 

• Destroy all metadata before the end of the five year authorized retention period (no exceptions for backup data) 



(TS//S I //M ^This staff will come in contact with human intelligible BR and PR/TT metadata. 
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(U) storage, Presentation, and Maintenance of the Metadata 



(U) Mission Capabilities 




(TS//SI//NF) Protocol Exploitation is 
responsible for: 

• Ensuring data is normalized and is 
presented in a usable format 

• Providing support to intelligence analysts 



(TG/i'SI//MF) For BR, erfonns unique functions including: 

Normalizing 

Reviewing data to ensure records include only data ^^^^^^^^^^^^^^^^H 

Assist in ensuring that data to be presented to analysts will be in a usable format 
Providing operational support to intelligence analysts; support is limited to RAS-approved identifiers 
within the authorized number of hops 



As you for PR/TT, ^^^^^^^^^^^pDrovides '"^^^^^^^^^^^^^^^^^^B^^^^^^l ^'-"^ 

BR, ^^^^^^^^^^^Kssists in ensuring accurate representation and integrity of the metadat^i^hi^ontext,^^^^^^^^^^H performs both a 

tech upporting role for intelligence analysts. Because of this dual role,^^^^^^^^^^^|must apply the rules governing the specific 

function it is performing at the time. WtieiyDerfomTin^^echnical role, the technical rules apply which allow/ broader access to the data. However, when 
supporting the intelligence analyst, the staff must operate within the same rules applicable to the intelligence analyst which are more 
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restrictive. 



( T S//S I //NF ) For BR, 



Iperforms unique functions to include: 
Normalizing all of the disparate data formats ^^^^^^^^^^^^^^^^^H 

Reviewing the data to validate that the records include only data^^^^^^^^^^^^^^^^^f 

Assist in ensuring that the data to be presented to the analysts will be in a usable format 

Providing operational support as necessary to intelligence analysts; support is limited to RAS-approved identifiers within the authorized number of 
hops 
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(U) Knowledge Checl< 2 

4. (TI3//3 l //f'jr) W hich one of these is not one of the roles and responsibilities of the technical personnel? 

a) (U//FOUO) Manipulating and validating the metadata to make it usable for intelligence analysis 
purposes 

b) (TO//O I //Nr) Developing new tools to support querying of BR and PR/TT metadata 

c) ^S//S I //REL )- Running an intelligence analysis query using a RAS-approved identifier for an analyst 
who is experiencing problems recreating their query results 

d) (S//S I //nEL) R unning an Intelligence analysis query using a non-RAS-approved identifier for 
an analyst who is experiencing problems recreating their query results 



e) (U) Both C and D 



arovides support to the BR program by doing the following (check all 



(TS//S I//N F) ^^^^^H^^ 
that apply): 

a) (U) Normalizing all of the disparate data formats 

b) (U) Reviewing the data to validate that the records include data 



c) (U) Ensuring metadata is maintained in secure NSA repositories. 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

e) (U) Destroy all metadata before the end of the five year authorized retention period (no exceptions 
for backup data 

f) (S//S I //RCL) Providing operational support as necessary to intelligence analysts on RAS- 
approved identifiers within the authorized number of hops 



nt and user interface professionals in 



6. (TO//G I //rjr) Database ^^^^ 

maintain, and operate the ^^^^flthat store and present BR and PR/TT metadata, and develop 
algorithms/processes that prepare, optimize, and characterize the metadata for analytic utilization. 

a) 

b) 

c) 

d) (U) Homeland Mission Coordinators 



develop, 



(U) (Technical Character): Let's check what you remember from this topic! 



Question 4. fPS#S<#N^ Correct! Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is experiencing problems 
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recreating their query results is not one of tlie roles and responsibilities of the technical personnel. 



(TO//O I //l'jr) Incorrect. The correct answer is d). Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is 
experiencing problems recreating their query results is not one of the roles and responsibilities of the technical personnel. 

Question 5. (T3//S I //Nr) Correct! ^^^^^^^^^^^^rovides support to the BR program by doing the following: 

a) (U) Normalizing all of the disparate data formats 

b) (U) Reviewing the data to validate that the records include data | 
d) (U) Assist In ensuring that the data to be presented to the analysts will be in a usable format 

f) (S//S I //RCL) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 
number of hoD^^^^^^^^^^ 
(TO//O I //Nr) Incorrect provides support to the BR program by doing the following: 

a) (U) Normalizing all of the disparate data formats ^^^^^^^^^^^^^^^^^^^k 

b) (U) Reviewing the data to validate that the records include data 

d) (U) Assist In ensuring that the data to be presented to the analysts will be in a usable format 

f) (S//S I //RCL) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 
number of hops 

K. (TS//S I //Nr) Correct! Database management and user interface professionals in Mission Capabilities develop, maintain, and operat( 
store and present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the metadata] 




and 



^TG/ZG I /Zriir ^-JDCoagcLThe correct answer is a). Database management and user interface professionals in Mission Capabilities develop, maintain 
operate t he ^^^^Bthat store a nd present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the 
metadata 
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(U) The Compliance Certification Process 

(U//FOUO) Compliance certification is a mandatory check for all systems handling U.S. 
person or FISA data 

(U) Guidelines governing the certification process are maintained by the TD Compliance 
Office 

(U) Compliance should be integrated into the development process 


(TO//GI//Nr) (Technical Character): Next we will discuss the compliance certification process used by technical personnel who develop mission 
technologies to Include those supporting the BR and PR/TT Programs. Compliance certification Is a mandatory check for all systems handling U.S. person 
or FISA data. Guidelines governing the certification process are maintained by the TD Compliance Office. This process supports compliance with the 
applicable laws and authorities and supports the NSA Way. The NSA Way Is a unified framework for building large (or small), complex, primarily software 
systems that meet the diverse needs of NSA missions. An Important point Is that compliance should be Integrated Into the development process. 
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(U) Following the Compliance Certification Process 

(U) The goal of the compliance certification process is to integrate compliance into the 
development phase 
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(T3//3 l //f'JF) (Technical Character): The goal of the compliance certification process is to integrate compliance into the development phase. The gates 
shown in the compliance process represent distinct requirements that must be satisfied in order to provide reasonable assurance of compliance. The 
architects of the new technology develop engineering documents to support these requirements. The TD certification group reviews the artifacts to verify 
the compliance process requirements are being met. 



(TO//O I //Nr ) The compliance certification process begins by registering in I 
browser. Once registration is complete, you will receive a requirements pa 



[Access the site by typing 



(U/T^t^UQ) Compliance is an ongoing process. Any change or update to previously certified software requires recertifi 
words, if you develop a modification or upgrade to the software, then you need to register the software modification in 
recertification process. 
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(TO//O I //Nr) Formal approval is required for all new and/or different BR and PR/TT systems. Under no circumstances can a change be made to a software 
system (even for testing purposes) without going through the compliance certification (or recertification) process. 
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(U//FOUO) Triggers for entering the dataflow governance process include (but are not 
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(TS//S I //Nr) (Technical Character): The Collection Strategies and Requirements Center (CSRC) is responsible for dataflow governance, which provides 
reasonable assurance of accountability and compliance for NSA mission data as it moves throughout NSA systems. This is critical to protect the data, and 
when we are talking about volumes of U.S. person data you can understand why this is so important. 

(TO//O I //Nr) The process begins by submitting a dataflow request (usually done by the system builder or access owner) for a new dataflow solution. Then 
some level of research is needed to determine the type of request and associated needs. Once the requirements are determined, a new processing 
capability may be developed, or an existing flow may be reconfigured to meet the new requirement. The solution must then be tested and obtain official 
sign-off at which time CSRC authorization to operate would be issued. 

(U/TPSl^^^^^^^^^^to^^j^the dataflow governance process include (but are not limited to): 

• Replacing an existing repository 

• Inserting a process or system into the flow 

• Adding a new mission element 

• Legacy migration (moving an existing unmanaged flow to a managed flow) 

(TS//S I //NF) Formal approval is required for all new and/or different BR and PR/TT data flows. Under no circumstances can a change be made to a data 
flow (even for testing purposes) without going through the dataflow governance process. 

(U// FOUO ) To find out more about the dataflow process, please refer to the Dataflow webpage by typing 'go dataflow' in your web browser. 
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(U) Knowledge Check 3 

7. (TS//S I //NF) The compliance certification process for new systems is triggered by 



a) (U) Entering a ticket into^^^^^l 

b) (U//FOUO) Contacting NSA Way Team 

c) (U//FOUO) Entering the new software or system Into | 

d) (U) All of the above 



8. {TS//SI//N^^hid^yh^QlJQwin£y^^^^ga|on for entering the dataflow governance process? 

b) (U^eplaon^^xistm^reposito^^ 

c) (U) Inserting a process or system into the flow 

d) (U) Modifying a bulk metadata query 

e) (U) Moving an existing unmanaged flow to a managed flow 

9. (TO//O I //riir) Before an analytic software upgrade is released on a system that handles BR or PR/TT data, 
the developers would need to in order to remain compliant. 

a) (U) contact the CSRC and undergo comDiiancygcertification 

b) (U) register the software release in^^^^^^^^^nnd undergo compliance recertification 



c) (U) obtain OGC approval 

d) (U) register your system with ODOC 



(U) (Technical Character): Let's make a few notes in our travel journal and check to see what you remember from this topic! 



^^^^^^^^^^^pWQi Correct! The compliance certification process for new systems is triggered by entering the new software or system in 

ct. The correct answer is c). The compliance certification process for new systems is triggered by entering the new software or system in 



Question 8. (U//F OUQ ) Correct! Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 
{U/!'FQUQjJncorrect. The correct answer is d). Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 

Question 9. (U/ /FOUO) Correct! Befoi^ai^nalvtic software upgrade is released on a system that handles BR or PR/TT data, the developers would need to 
register the software release in ^^^^^^^^nnd undergo compliance recertification in order to remain compliant. 

(U //rOUO ) Incorrect. The corre^^^^^^^^ ^efore an analy tic software upgrade is released on a system that handles BR or PR/TT data, the developers 
would need to register the software reli i i in ^^^^^^^^Bnnd undergo compliance recertification in order to remain compliant. 
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(U) Practice Scenario 1 

(TO//O I //Nr) You are one of the ^^^^^^^^|cleared technic^^^^^^^^ponsible for metadata management 

within NSA's metadata reoositones. You are working with other ^^^^^^^H-cleared developers on new query 

processes and tools. You ^^^|a set of properly marked recor y your team for development 

purposes from the PR/TT metadata. This set of PRATT metadata records is stored on a physically isolated system 
within NSA's secure network and is accessible only to the members of your team. Are your actions in 
compliance with the terms of the PR/TT Orders? 

(U) Please select the BEST answer: 

a) (TS//S I //Nr) Yes, because the PR/TT Orders explicitly authorize properly trained technical 
personnel to develop and test new technologies to be used with the PR/TT metadata. 

b) (T3//0I//NR-) No, because the PR/TT Orders prohibit the use of new query processes against any of 
the PF^TT metadata. 

c) (TO//O I //Nr) Yes, because the^^^^^^^^HP'^'TT metadata records still carry the unique 
markings and softwaE^ontrQl^on the physically isolated system to restrict access to 
those records to^^^^^^^^|cleared personnel. 

d) (U) None of the above are correct. 



(U) (Technical Character): Now let's practice what we have learned using real-life scenarios. Carefully read the scenario and then select the best answer. 



ANSWER: 

a) (TO//O I //Nr) I n co rrect. This statement is accurate, but this is not what makes your actions compliant. The correct answer is c). Yes, because the 
^^^^^^^^ ^RfTJ metadata r ecords still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records to ^^^^^^^^^leared personnel. 

^^//S l //N ^^ncprrect. The current Court Orders authorize NSA to develop new query processes. The correct answer is c). Yes, because the 

^R/TT metadata records still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records to ^^^^^^^^|cleared personnel. ^^^^^^^^^h 

c) (TS/ZOIZ/Nr)- Correct! The best answer is c). Yes, because the ^^^^^^^^^FR/TT metadatmecoix|^tiM carry the unique markings and 
software controls on the physically isolated system to restric^^^^^^^^^e records to ^^^^^^^^^cleared personnel. 

d) (TS//S I //NF) Incorrect. The correct answer is c). Yes, because the^^^^^^^^|PR/T"niTetadat^2Cords still carry the unique markings and 
software controls on the physically isolated system to restrict access to those records to ^^^^^^^^Bcleared personnel. 
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(U) Practice Scenario 

(TG//S I //Nr) You are a ^^^^^^^H-cleared developer of contact chaining analytic tools. Your 
management chain has requeste^^iefing to demonstrate your progress on the latest version of the tool. 
You provide the briefing, which includes screen shots of the tool and query results generated by the tool. Are 
your actions in compliance with the Orders? 

(U) Please select the BEST answer: 

a) (U/ /rOUO) No, unless all of those or^oui^eveloDment team and all those who 
attended your briefing held current ^^^^^^^^Iclearances. 

b) (U) No, because the Court Orders do not permit testing of tools under development using 
real data. 

c) (U) Yes, as long as the query results shared during the briefing are never used for 
intelligence analysis purposes. 

d) (U) None of the above are correct. 



ANSWER: 

a) (U) Correct! This is the best answer. You cannot provide a demonstration unless all of the individuals who attended the briefing have 
completed the required training and received the necessary accesses. 

b) (U/7FQ UP) Incorrect. Th e correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current ^^^^^^^^|clearances. 

c) (U//FT5yQ^ncoiTec^^e correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current ^^^^^^^^Klearances. 

d) (UZ/Fo yQ) Incorrect. Th e correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current ^^^^^^^^Klearances. 
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(U) Practice Scenario 3 ^^^^^^^^^ 

{TS//SI//NF) You are one of the^^^^^^^^ftcleared technical personnel responsible for metadata 
management within NSA's metadata repositories. You are responsible for the maintenance of backup 
systems and Continuity of Operations (COOP) planning and implementation. You have contro^ver the 
backup tapes that hold PR/TT metadata collected since the inception of the PR/TT authority^^^H In 

accordance with your COOP plans, you know that if a disaster strikes and NSA's online metaoat^^ 
repositories are destroyed, you could use these backup tapes to repopulate the repositories with PR/TT 
metadata. Although the backup tapes contain information older than five years, the processes you would 
employ to repopulate the online analytic metadata repositories would select only metadata collected within 
the last five years. Is your maintenance of backup tapes holding PFWTT metadata collected more than five 
years ago in compliance with the terms of the PR/TT Orders? 

(U) Please select the BEST answer: 

a) (TG//OI//Nr) Yes, because the older-than-five-years PF?/TT metadata on the backup tapes 
will never be available for intelligence analysis purposes. 

b) (TS//SI//NF) Yes, because the PR/TT Orders specifically authorize NSA to maintain backup 
tapes of the PR/TT metadata. 

c) (TS//SI//NF) No, because the PR/TT Orders mandate the destruction of the PR/TT 
metadata no later than five years after its initial collection, with no exception for 
metadata on backup tapes. 

d) (U) None of the above are correct. 


ANSWER: 

a) (TS//SI//Nr) Incorrect. The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. This is different from other authorities, for example FAA 702 does 
not require the destruction of data in the archives. 

b) (T0//SI//I'4F) Incorrect. The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PFWTT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 

c) (TS//SI//NF) Correct! This is the best answer. No, because the PR/TT Orders mandate the destruction of tlie PR/TT metadata no later than 
five years after its initial collection, with no exception for metadata on backup tapes. 

d) (TS//SI//NF) Incorrect. The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 
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(U) Now that you have completed this module you should be able to: 

• (TG//OI//Nr) Identify the various technical roles that support the BR and PR/TT Bulk 

ividdUdLci 1 1 1 cii 1 lo 

• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission 
systems and data flows 

• (TO//OI//Nr) Practice applying BR and PR/TT authorities in real-life scenarios 
applicable to technical personnel 

(U//rOUO)- If you have questions or wish to find out more, please contact your manager or 
any of the following BR or PR/TT points of contact: 

TD Compliance Office website: go td compliance 

alias: ^^^^^^1 




Phone: 
OGC website: go GC 

Oversight and Compliance email alias: DL SV42_all 






(TO//OI//Nr) (Technical Character): As we stated earlier in the course, the bulk metadata includes sensitive data that must be protected accordingly. By 
nature of the kinds of technical support provided to the BR and PR/TT programs, technical personnel have the authority and unrestricted access to touch 
unminimized/unevaluated (or raw), and very sensitive data (that contains a lot of U.S. person identifiers). Remember, we need to maintain a clear 
distinction between the roles of technical and analytical personnel. All personnel are held to a high standard of integrity, but in your technical role you must 
be particularly cautious because the tools you work with do not provide the same safeguards as those tools used by the analytical personnel. 
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( TS//S I //Nr) In conclusion, It Is your responsibility to keep the BR and PR/TT Information wltfiin the confines of those who have the proper authorizations to 
touch and view the data. 

(U) Now that we have completed this part of our road trip, you should be able to: 

• ( TO//O I //Nr ) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 

• (U) Identify the responsibilities of each of the technical roles 

• (U) Recognize key points of the compliance certification process for mission systems and data flows 

• (TS//S I //NF) Practice applying BR and PR/TT authorities In real-life scenarios applicable to technical personnel 

(U) You are encouraged to reach out to your management or to any of the points of contact listed here If you have any questions or If you want to find out 
more. 
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(U) PLEASE READ: Important Assessment Information 

• (U) You will view the questions in a separate Assessment Questions Document 

• (U) You will enter your responses in a separate QuestionMark online answer sheet 

• (U) You will have only one attempt to successfully complete the assessment 

• (U) Allow yourself sufficient time (approximately 30 minutes) to complete the assessment 

(U) To Complete the Assessment: 

• (U) Click the link to open the Assessment Questions Document! 



(U) Go to the VUport SumTotal Content Player page, click on the Assessment link, and follow the 
instructions to complete the required exam 



Comment [SLSl]: Please make this a link that 
will open the Assessment Question pdf for 
Analytical Personnel {we will actually connect the 
link later). 



(Utf FOUO - ) (OGC Attorney): The final part of your trip will be to successfully complete the assessment for the course. Please be aware that for the 
assessment you will view the questions in a .pdf file and enter your responses in a separate QuestionMark online answer sheet. Please be sure that you 
open the .pdf with the questions first before opening the QuestionMark online answer sheet. You will have one attempt to complete the assessment. Please 
allow yourself sufficient time (approximately 30 minutes) to complete the assessment. 

(U/ /FOUO) Please click the Assessment Questions Document link to open the .pdf question file and keep the window open. Then go to the VUport 
SumTotal Content Player page, click on the Assessment link on the left, and follow the instructions to complete the required exam. 
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